CVE-2023-22945Incorrect Authorization in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 68.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11

Description

In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

Also affects: Fedora 37

Patches

🔴Vulnerability Details

1
GHSA
GHSA-p28r-f42x-qmm2: In the GrowthExperiments extension for MediaWiki through 12023-01-11

📋Vendor Advisories

1
Red Hat
mediawiki: GrowthExperiments growthmanagementorlist API allows blocked users to enroll as mentors2023-01-11
CVE-2023-22945 — Incorrect Authorization in Mediawiki | cvebase