Cross-Site Request Forgery (CSRF) Vulnerability in Mediawiki - Cargo
CVE-2024-47846

8.8HIGH

Key Information:

Vendor
CVE Published:
5 October 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wikimedia Foundation's Mediawiki - Cargo extension, enabling attackers to trick users into executing harmful requests without their consent. This vulnerability affects versions 3.6.X, prior to 3.6.1. If exploited, it could lead to unauthorized actions being performed on behalf of users, jeopardizing the integrity of user data and the overall application. Prompt application of security patches is crucial for affected users to mitigate potential risks.

Affected Version(s)

Mediawiki - Cargo 3.6.x < 3.6.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BlankEclair
Yaron_Koren
.