
Cloud Vulnerability DB
A community-led vulnerabilities database
The Private Domains extension for MediaWiki through version 1.37.2 (before commit 1ad65d4c1c19) contained a Cross-Site Request Forgery (CSRF) vulnerability that affected the page editing functionality (NVD).
The vulnerability existed in the Special:PrivateDomains form which allowed editing pages in NS_MEDIAWIKI namespace used for storing PrivateDomains settings. The form lacked proper anti-CSRF token implementation, only verifying that the request was POSTed and the action was 'submit' without any CSRF protection (Phabricator).
An attacker could potentially trick authenticated users into making unwanted changes to the PrivateDomains settings through CSRF attacks, effectively modifying the extension's configuration without the user's knowledge or consent (Phabricator).
The vulnerability was fixed by adding proper anti-CSRF token validation to the edit form. Users should upgrade to a version after commit 1ad65d4c1c19, which implements the security fix by adding wpEditToken validation (Phabricator).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."