Vulnerability Name: | CVE-2014-3455 (CCN-93582) | ||||||||
Assigned: | 2014-01-14 | ||||||||
Published: | 2014-01-14 | ||||||||
Updated: | 2014-05-13 | ||||||||
Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special pages in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow remote attackers to hijack the authentication of users for requests that have unspecified impact and vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3455 Source: CCN Type: MediaWiki Security Releases [MediaWiki-announce- MediaWiki Security Releases: 1.22.1,1.21.4 and 1.19.10 Source: MLIST Type: Patch, Vendor Advisory [MediaWiki-announce] 20140114 MediaWiki Security Releases: 1.22.1, 1.21.4 and 1.19.10 Source: CCN Type: MediaWiki Web site MediaWiki Source: CCN Type: Bugzilla Bug 57025 Add CSRF checks to Special:CreateCategory Source: CONFIRM Type: UNKNOWN https://bugzilla.wikimedia.org/show_bug.cgi?id=57025 Source: XF Type: UNKNOWN semanticforms-mediawiki-cve20143455-csrf(93582) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||
BACK |