Description
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery Master-Responsive Photo Galleries & Albums Cross-Site Scripting (1.0.22)
WordPress Plugin Software License Manager Cross-Site Request Forgery (4.4.5)
Apache HTTP Server Other Vulnerability (CVE-2001-1449)
WordPress Plugin Side Menu-add fixed side buttons SQL Injection (3.1.3)