CVE-2023-45374: CSRF
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-45374.
What is the severity of CVE-2023-45374?
The severity of CVE-2023-45374 is medium.
What is the affected software?
The affected software is MediaWiki versions before 1.35.12, versions 1.36.x through 1.39.x before 1.39.5, and version 1.40.x before 1.40.1.
How does CVE-2023-45374 impact MediaWiki?
CVE-2023-45374 allows attackers to bypass the anti-CSRF edit token in the Special:SportsTeamsManager and Special:UpdateFavoriteTeams pages of MediaWiki.
Are there any references for CVE-2023-45374?
Yes, you can find references for CVE-2023-45374 at the following links: [Link 1](https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/952552/) and [Link 2](https://phabricator.wikimedia.org/T345040).