Description
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.
Remediation
References
Related Vulnerabilities
Envoy Proxy Out-of-bounds Write Vulnerability (CVE-2019-18801)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-8656)
Zikula Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-2293)
WordPress Plugin WP Better Permalinks Cross-Site Request Forgery (3.0.4)