Description
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.
Remediation
References
Related Vulnerabilities
qdPM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11811)
WordPress Plugin 3D Banner Rotator 'upload.php' Arbitrary File Upload (2.1)
WordPress Plugin Membership Simplified Multiple SQL Injection Vulnerabilities (1.58)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2007-5899)