Description
Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the centralauth_Session cookie.
Remediation
References
Related Vulnerabilities
MySQL CVE-2016-3486 Vulnerability (CVE-2016-3486)
Zikula Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-0535)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-29004)
WordPress Plugin Subscriptions & Memberships for PayPal Unspecified Vulnerability (1.1.5)
WordPress Plugin Product Size charts for Woocommerce Unspecified Vulnerability (1.0)