CVE-2014-3454: CSRF
Cross-site request forgery (CSRF) vulnerability in Special:CreateCategory in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to hijack the authentication of users for requests that create categories via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3454?
CVE-2014-3454 is classified as a high severity vulnerability due to its potential for cross-site request forgery attacks.
How do I fix CVE-2014-3454?
To fix CVE-2014-3454, you should upgrade MediaWiki to versions 1.19.10, 1.21.4, or 1.22.1 or later.
What software is affected by CVE-2014-3454?
CVE-2014-3454 affects MediaWiki versions prior to 1.19.10, 1.21.4, and 1.22.1 as well as certain 1.21.x versions.
What type of vulnerability is CVE-2014-3454?
CVE-2014-3454 is a cross-site request forgery (CSRF) vulnerability.
Can CVE-2014-3454 lead to account hijacking?
Yes, CVE-2014-3454 can allow remote attackers to hijack user authentication for category creation.