An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-23292 An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T17:09:15.104Z

Reserved: 2020-12-21T00:00:00

Link: CVE-2020-35626

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-21T23:15:12.577

Modified: 2024-11-21T05:27:43.677

Link: CVE-2020-35626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.