Cross-Site Request Forgery (CSRF) Vulnerability in Mediawiki - Cargo
CVE-2024-47846
8.8HIGH
What is CVE-2024-47846?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wikimedia Foundation's Mediawiki - Cargo extension, enabling attackers to trick users into executing harmful requests without their consent. This vulnerability affects versions 3.6.X, prior to 3.6.1. If exploited, it could lead to unauthorized actions being performed on behalf of users, jeopardizing the integrity of user data and the overall application. Prompt application of security patches is crucial for affected users to mitigate potential risks.
Affected Version(s)
Mediawiki - Cargo 3.6.x < 3.6.1
