CVE-2014-3455: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special pages in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow remote attackers to hijack the authentication of users for requests that have unspecified impact and vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3455?
CVE-2014-3455 is categorized as a moderate severity vulnerability due to various cross-site request forgery (CSRF) risks.
How do I fix CVE-2014-3455?
To mitigate CVE-2014-3455, upgrade to MediaWiki versions 1.19.10, 1.21.4, or 1.22.1 and apply the related patches.
What are the affected versions for CVE-2014-3455?
CVE-2014-3455 affects MediaWiki versions before 1.19.10, versions in the 1.2x series before 1.21.4, and all versions in the 1.22.x series before 1.22.1.
What types of attacks can CVE-2014-3455 enable?
CVE-2014-3455 can enable remote attackers to perform actions on behalf of authenticated users through cross-site request forgery.
Is there a workaround for CVE-2014-3455?
While updating is the best solution, temporarily disabling the affected special pages may help mitigate the risks associated with CVE-2014-3455.