CSRF Vulnerability in MediaWikiChat Extension
CVE-2024-40601

6.5MEDIUM

Key Information:

Vendor

MediaWiki

Status
Vendor
CVE Published:
7 July 2024

What is CVE-2024-40601?

A vulnerability has been identified in the MediaWikiChat extension for MediaWiki, where Cross-Site Request Forgery (CSRF) can occur in specific API modules. This issue affects MediaWikiChat versions up to 1.42.1, potentially allowing unauthorized execution of actions on behalf of users without their consent. This flaw highlights the importance of implementing robust security measures to prevent CSRF attacks, which can compromise user data and system integrity. Adopting best practices in securing web applications is essential for mitigating such vulnerabilities.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.