Cross-Site Request Forgery (CSRF) Vulnerability in Mediawiki - Cargo
CVE-2024-47846
8.8HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wikimedia Foundation's Mediawiki - Cargo extension, enabling attackers to trick users into executing harmful requests without their consent. This vulnerability affects versions 3.6.X, prior to 3.6.1. If exploited, it could lead to unauthorized actions being performed on behalf of users, jeopardizing the integrity of user data and the overall application. Prompt application of security patches is crucial for affected users to mitigate potential risks.
Affected Version(s)
Mediawiki - Cargo 3.6.x < 3.6.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
BlankEclair
Yaron_Koren