CVE-2024-40603: CSRF
Published Jul 6, 2024
·Updated
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.42.1
Event History
Jul 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jul 7, 2024
Data Sourced
via NVD·12:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-40603?
CVE-2024-40603 has a moderate severity level due to its potential for cross-site request forgery (CSRF).
2
How do I fix CVE-2024-40603?
To mitigate CVE-2024-40603, upgrade the ArticleRatings extension for MediaWiki to a version higher than 1.42.1.
3
What software is affected by CVE-2024-40603?
CVE-2024-40603 affects all versions of the ArticleRatings extension for MediaWiki up to and including 1.42.1.
4
What type of vulnerability is CVE-2024-40603?
CVE-2024-40603 is a cross-site request forgery (CSRF) vulnerability that allows data alteration via a GET request.
5
Can CVE-2024-40603 be exploited remotely?
Yes, CVE-2024-40603 can be exploited remotely due to its reliance on GET requests, making it accessible to an attacker.