First published: Fri Apr 29 2022(Updated: )
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | <=1.37.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-29906 is classified as medium due to the potential unauthorized access to admin functions.
To fix CVE-2022-29906, upgrade to MediaWiki version 1.37.3 or later where the vulnerability has been patched.
CVE-2022-29906 affects MediaWiki versions up to and including 1.37.2.
CVE-2022-29906 exploits a lack of user checks in the admin API module of the QuizGame extension.
Yes, if you are running MediaWiki version 1.37.3 or newer, your installation is safe from CVE-2022-29906.