CVE-2019-15150: CSRF
Published Aug 19, 2019
·Updated
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
Affected Software
1 affected component
Schine.games Mw-oauth2client<0.4
Remediation
Event History
Aug 19, 2019
CVE Published
via MITRE·03:41 AM
Data Sourced
via MITRE·03:41 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15150?
CVE-2019-15150 is classified as a medium severity vulnerability due to its potential for CSRF attacks.
2
How do I fix CVE-2019-15150?
To fix CVE-2019-15150, upgrade the MiniOrange OAuth 2.0 Client for SSO extension to version 0.4 or later.
3
What type of vulnerability is CVE-2019-15150?
CVE-2019-15150 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What impact does CVE-2019-15150 have on MediaWiki?
CVE-2019-15150 could allow an attacker to perform actions on behalf of the user without their consent.
5
Is CVE-2019-15150 specific to any version of the OAuth2 Client extension?
Yes, CVE-2019-15150 affects the OAuth2 Client extension versions below 0.4.