Description
The transwiki import functionality in MediaWiki before 1.16.3 does not properly check privileges, which allows remote authenticated users to perform imports from any wgImportSources wiki via a crafted POST request.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP HTML Author Bio Cross-Site Scripting (1.2.0)
phpMyFAQ Other Vulnerability (CVE-2005-3734)
PrestaShop Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-8823)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-3394)