Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-03946
HistoryJan 14, 2022 - 12:00 a.m.

MediaWiki Cross-Site Request Forgery Vulnerability (CNVD-2022-03946)

2022-01-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

EPSS

0.001

Percentile

41.8%

MediaWiki is a free, free-to-use web-based wiki engine from the MediaWiki Foundation. The product can be used to deploy internal knowledge management and content management systems.A cross-site request forgery vulnerability exists in MediaWiki, which stems from a failure of the product’s MassEditRegex to determine that requests originate from trusted users. An attacker could send an unintended request through this vulnerability.

EPSS

0.001

Percentile

41.8%