Description
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin GeoDirectory Location Manager Multiple SQL Injection Vulnerabilities (2.1.0.9)
WordPress Plugin SSL Insecure Content Fixer Information Disclosure (2.0.0)
WordPress Plugin WP DoNotTrack Cross-Site Scripting (0.8.8)
WordPress Plugin Attachment File Icons (AF Icons) Cross-Site Request Forgery (1.3)