PT-2021-19920 · Mediawiki · Datadump
Redmin
·
Published
2021-07-20
·
Updated
2021-07-28
·
CVE-2021-32774
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DataDump versions prior to commit 67a82b76e186925330b89ace9c5fd893a300830b
Description
The issue concerns a lack of protection against CSRF attacks in the DataDump MediaWiki extension, allowing forged requests to generate or delete dumps. There are no known workarounds.
Recommendations
For versions prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, completely disable DataDump as there is no other known mitigation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datadump