#VU26570 Open redirect in MediaWiki
Published: April 3, 2020
MediaWiki
MediaWiki.org
Description
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data, related to logout URL. A remote attacker can redirect the victim to an arbitrary domain via the logout button.
Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.