Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 71.3%