Vulnerability Name: | CVE-2014-3454 (CCN-93584) | ||||||||
Assigned: | 2014-01-14 | ||||||||
Published: | 2014-01-14 | ||||||||
Updated: | 2014-05-13 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in Special:CreateCategory in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to hijack the authentication of users for requests that create categories via unspecified vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3454 Source: CCN Type: MediaWiki Security Releases [MediaWiki-announce- MediaWiki Security Releases: 1.22.1,1.21.4 and 1.19.10 Source: MLIST Type: Patch, Vendor Advisory [MediaWiki-announce] 20140114 MediaWiki Security Releases: 1.22.1, 1.21.4 and 1.19.10 Source: CCN Type: MediaWiki Web site MediaWiki Source: CCN Type: BID-67522 MediaWiki 'Special:CreateCategory' CVE-2014-3454 Cross Site Request Forgery Vulnerability Source: CCN Type: Bugzilla Bug 57025 Add CSRF checks to Special:CreateCategory Source: CONFIRM Type: UNKNOWN https://bugzilla.wikimedia.org/show_bug.cgi?id=57025 Source: XF Type: UNKNOWN semanticforms-mediawiki-cve20143454-csrf(93584) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||
BACK |