Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to hijack the authentication of users for requests that login via vectors involving image loading.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2013-12-13T18:00:00

Updated: 2013-12-13T17:57:00

Reserved: 2012-10-17T00:00:00


Link: CVE-2012-5394

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2013-12-13T18:07:53.750

Modified: 2013-12-16T15:24:47.617


Link: CVE-2012-5394

JSON object: View

cve-icon Redhat Information

No data.

CWE