CVE-2023-45370: Medium severity mediawiki vulnerability
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45370?
CVE-2023-45370 is an issue discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
What is the severity of CVE-2023-45370?
CVE-2023-45370 has a severity rating of medium (5.3).
How does CVE-2023-45370 impact MediaWiki?
CVE-2023-45370 affects the SportsTeams extension of MediaWiki, allowing an attacker to bypass user rights checks.
How can I fix CVE-2023-45370?
To fix CVE-2023-45370, it is recommended to upgrade to MediaWiki version 1.35.12, 1.39.5, or 1.40.1, depending on the currently installed version.
Where can I find more information about CVE-2023-45370?
More information about CVE-2023-45370 can be found at the following references: [Link 1](https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/959699/) and [Link 2](https://phabricator.wikimedia.org/T345680).