Impact
The user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the other wiki can act as if they're the original wiki requester. This can be abused to create new comments, edit the request, and view the request if it's marked private.
Patches
Workarounds
It is possible to disable the special page outside of your global wiki by doing something similar to miraheze/mw-config@e566499. You must adapt that to your setup.
References
Impact
The user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the other wiki can act as if they're the original wiki requester. This can be abused to create new comments, edit the request, and view the request if it's marked private.
Patches
Workarounds
It is possible to disable the special page outside of your global wiki by doing something similar to miraheze/mw-config@e566499. You must adapt that to your setup.
References