First published: Mon Oct 09 2023(Updated: )
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <1.35.12 | |
MediaWiki MediaWiki | >=1.36.0<1.39.5 | |
MediaWiki MediaWiki | =1.40.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45370 is an issue discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
CVE-2023-45370 has a severity rating of medium (5.3).
CVE-2023-45370 affects the SportsTeams extension of MediaWiki, allowing an attacker to bypass user rights checks.
To fix CVE-2023-45370, it is recommended to upgrade to MediaWiki version 1.35.12, 1.39.5, or 1.40.1, depending on the currently installed version.
More information about CVE-2023-45370 can be found at the following references: [Link 1](https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/959699/) and [Link 2](https://phabricator.wikimedia.org/T345680).