Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2019-15150
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
51.9%
CVSS Severity
CVSS v3 Score
8.8
CVSS v2 Score
6.8
References
http://packetstormsecurity.com/files/154140/MediaWiki-OAuth2-Client-0.3-Cross-Site-Request-Forgery.html
http://seclists.org/fulldisclosure/2019/Aug/25
http://www.openwall.com/lists/oss-security/2019/08/19/1
https://github.com/Schine/MW-OAuth2Client/commit/6a4fe4500ddd72ad4e826d9d63b2d69512bd10d1
https://github.com/Schine/MW-OAuth2Client/releases/tag/v0.4
https://seclists.org/bugtraq/2019/Aug/32
http://packetstormsecurity.com/files/154140/MediaWiki-OAuth2-Client-0.3-Cross-Site-Request-Forgery.html
http://seclists.org/fulldisclosure/2019/Aug/25
http://www.openwall.com/lists/oss-security/2019/08/19/1
https://github.com/Schine/MW-OAuth2Client/commit/6a4fe4500ddd72ad4e826d9d63b2d69512bd10d1
https://github.com/Schine/MW-OAuth2Client/releases/tag/v0.4
https://seclists.org/bugtraq/2019/Aug/32
Products affected by CVE-2019-15150
Schine.games
»
Mw-Oauth2client
»
Version:
N/A
cpe:2.3:a:schine.games:mw-oauth2client:-
Schine.games
»
Mw-Oauth2client
»
Version:
0.2
cpe:2.3:a:schine.games:mw-oauth2client:0.2
Schine.games
»
Mw-Oauth2client
»
Version:
0.3
cpe:2.3:a:schine.games:mw-oauth2client:0.3
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved