CVE-2023-45370
SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- mediawiki/mediawiki
- Source
- cve@mitre.org
References
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/959699/Issue Tracking, Vendor Advisory
- https://phabricator.wikimedia.org/T345680Issue Tracking, Vendor Advisory
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/959699/Issue Tracking, Vendor Advisory
- https://phabricator.wikimedia.org/T345680Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.