Description
MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social Media Share Buttons & Social Sharing Icons Cross-Site Scripting (1.1.1.11)
MySQL CVE-2020-2752 Vulnerability (CVE-2020-2752)
MySQL CVE-2018-2782 Vulnerability (CVE-2018-2782)
Oracle JRE CVE-2019-2983 Vulnerability (CVE-2019-2983)
Joomla URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2015-5608)