Cross-Site Request Forgery Vulnerability in MediaWiki
CVE-2021-46147

8.8HIGH

Key Information:

Vendor

Mediawiki

Status
Vendor
CVE Published:
10 January 2022

What is CVE-2021-46147?

A vulnerability in MediaWiki, prior to versions 1.35.5, 1.36.3, and 1.37.1, enables malicious actors to exploit MassEditRegex, allowing the execution of unauthorized actions on behalf of authenticated users. This flaw can lead to potentially harmful modifications without user consent or awareness, posing significant security risks to web applications utilizing MediaWiki.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.