Description
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0716 | Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token. |
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-09-16T20:22:32.537Z
Reserved: 2016-11-29T00:00:00.000Z
Link: CVE-2017-0362
No data.
Status : Modified
Published: 2018-04-13T16:29:00.347
Modified: 2024-11-21T03:02:50.180
Link: CVE-2017-0362
OpenCVE Enrichment
No data.
EUVD