CVE-2025-11173: Reauth for enabling 2FA can be bypassed by submitting a form
Vulnerability in Wikimedia Foundation OATHAuth. This vulnerability is associated with program files src/Special/OATHManage.Php.
This issue affects OATHAuth: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11173?
The severity of CVE-2025-11173 is considered high due to the potential for bypassing two-factor authentication.
How do I fix CVE-2025-11173?
To fix CVE-2025-11173, upgrade to OATHAuth version 1.39.14 or later, or any version above 1.43.4 and 1.44.1.
What software is affected by CVE-2025-11173?
CVE-2025-11173 affects Wikimedia Foundation OATHAuth versions prior to 1.39.14, and between 1.43.4 and 1.44.1.
What exploit does CVE-2025-11173 represent?
CVE-2025-11173 represents a vulnerability that allows the reauthentication process required for two-factor authentication to be bypassed by improper form submission.
Who is responsible for addressing CVE-2025-11173?
The responsibility for addressing CVE-2025-11173 falls to users of the affected versions of Wikimedia Foundation OATHAuth.