Description
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
Remediation
References
Related Vulnerabilities
WordPress Plugin Post to CSV by BestWebSoft Cross-Site Scripting (1.3.0)
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26273)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2009-1890)
Oracle Database Server CVE-2014-6567 Vulnerability (CVE-2014-6567)
WebLogic Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1324)