ZeroHour

CVE-2023-45374

CVSS 3.1
5.3 medium
EPSS
<1%p8
Published
()
Modified
Description

An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.

Vendors
mediawiki
Products
mediawiki
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.