First published: Sat Jul 06 2024(Updated: )
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | <=1.42.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40603 has a moderate severity level due to its potential for cross-site request forgery (CSRF).
To mitigate CVE-2024-40603, upgrade the ArticleRatings extension for MediaWiki to a version higher than 1.42.1.
CVE-2024-40603 affects all versions of the ArticleRatings extension for MediaWiki up to and including 1.42.1.
CVE-2024-40603 is a cross-site request forgery (CSRF) vulnerability that allows data alteration via a GET request.
Yes, CVE-2024-40603 can be exploited remotely due to its reliance on GET requests, making it accessible to an attacker.