ZeroHour

CVE-2021-21275

CVSS 3.1
4.3 medium
EPSS
<1%p52
Published
()
Modified
Description

The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of MediaWiki edit tokens.

Vendors
report projectoracle
Products
report, communications cloud native core network slice selection function, communications pricing design center
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.