Description
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat user" who has a similar username, as demonstrated by usernames that differ only in (1) bidirectional override symbols or (2) blank space.
Remediation
References
Related Vulnerabilities
WordPress Plugin My WP Translate Multiple Vulnerabilities (1.0.3)
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-8980)
Joomla Inadequate Encryption Strength Vulnerability (CVE-2021-23126)
WordPress Plugin Connections Business Directory CSV Injection (9.6)
WordPress Plugin Custom Body Class Cross-Site Request Forgery (0.6.0)