Description
Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the centralauth_Session cookie.
Remediation
References
Related Vulnerabilities
CakePHP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-35239)
Roundcube Cross-site Scripting (XSS) Vulnerability (CVE-2015-8793)
Lodash CVE-2018-3721 Vulnerability (CVE-2018-3721)
Joomla! Core 4.x.x Multiple Vulnerabilities (4.0.0 - 4.2.6)
WordPress Plugin WPFront Notification Bar Cross-Site Scripting (1.9.1.04012)