Lucene search

K
osvGoogleOSV:CVE-2020-35626
HistoryDec 21, 2020 - 11:15 p.m.

CVE-2020-35626

2020-12-2123:15:12
Google
osv.dev
2

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.1%

An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.1%

Related for OSV:CVE-2020-35626