Schine/MW-OAuth2Client

Schine/MW-OAuth2Client

Releases1
Frequency
Last Release
Stars22
MediaWiki OAuth2 Client Extension

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.8 MEDIUM

In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.