The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of MediaWiki edit tokens.
2021-01-25T23:15:11.887
2024-11-21T05:47:54.657
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | report_project | report | < 2021-01-21 | Yes |
Application | oracle | communications_cloud_native_core_network_slice_selection_function | 1.2.1 | Yes |
Application | oracle | communications_pricing_design_center | 12.0.0.4.0 | Yes |
Application | oracle | communications_pricing_design_center | 12.0.0.5.0 | Yes |