CVE-2023-22945: Medium severity mediawiki vulnerability
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-22945.
What is the severity rating of CVE-2023-22945?
The severity rating of CVE-2023-22945 is medium (4.3).
Which software is affected by CVE-2023-22945?
The GrowthExperiments extension for MediaWiki up to version 1.39 and Fedora 37 are affected by CVE-2023-22945.
How can blocked users exploit CVE-2023-22945?
Blocked users can enroll as mentors or edit mentorship-related properties through the growthmanagementorlist API in MediaWiki.
Are there any references or additional information about CVE-2023-22945?
Yes, you can find more information about CVE-2023-22945 on the following URLs:<br>- [https://gerrit.wikimedia.org/r/q/Id1b83fcd58eccb8b2dfea44a3ab2f72314860d88](https://gerrit.wikimedia.org/r/q/Id1b83fcd58eccb8b2dfea44a3ab2f72314860d88)<br>- [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A/)<br>- [https://phabricator.wikimedia.org/T321733](https://phabricator.wikimedia.org/T321733)