VulnerabilityModified
CVE-2023-45374
It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.
MEDIUM 5.3EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- mediawiki/mediawiki
- Source
- cve@mitre.org
References
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/952552/Issue Tracking, Vendor Advisory
- https://phabricator.wikimedia.org/T345040Issue Tracking, Vendor Advisory
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/952552/Issue Tracking, Vendor Advisory
- https://phabricator.wikimedia.org/T345040Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.