{
  "modified": "2025-08-09T19:01:26Z",
  "published": "2010-06-08T00:30:01Z",
  "id": "CVE-2010-1648",
  "details": "Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to hijack the authentication of users for requests that (1) create accounts or (2) reset passwords, related to the Special:Userlogin form.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html"
    },
    {
      "type": "FIX",
      "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.wikimedia.org/show_bug.cgi?id=23371"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043803.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043856.html"
    }
  ]
}
