Vulnerability Description
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | < 1.35.12 |
Related Weaknesses (CWE)
References
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/952552/Issue TrackingVendor Advisory
- https://phabricator.wikimedia.org/T345040Issue TrackingVendor Advisory
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/952552/Issue TrackingVendor Advisory
- https://phabricator.wikimedia.org/T345040Issue TrackingVendor Advisory
FAQ
What is CVE-2023-45374?
CVE-2023-45374 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Spec...
How severe is CVE-2023-45374?
CVE-2023-45374 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45374?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki.