Description
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.
Remediation
References
Related Vulnerabilities
WordPress Plugin Data Tables Generator by Supsystic Cross-Site Scripting (1.10.0)
WordPress Plugin MP3-jPlayer Multiple Cross-Site Scripting Vulnerabilities (1.8.11)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-1333)