← Back

Mw Oauth2client

mw-oauth2client

Vendor: Schine.games • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schine.games
1Mw Oauth2client
Jun 17, 2026
Aug 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.