CVE-2020-29004
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.
HIGH · CVSS 8.8
EPSS 0.00156
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0