Open redirect in MediaWiki - #VU26570
Published: April 3, 2020
MediaWiki
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data, related to logout URL. A remote attacker can redirect the victim to an arbitrary domain via the logout button.
Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.