PT-2022-16893 · Miraheze · Createwiki

Rhinosf1

·

Published

2022-04-04

·

Updated

2023-06-23

·

CVE-2022-24813

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CreateWiki (affected versions not specified)
Description CreateWiki is Miraheze's MediaWiki extension for requesting and creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available in the master branch of CreateWiki's GitHub repository.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass Using an Alternate Path or Channel

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-24813
GHSA-9XVW-W66V-PRVG

Affected Products

Createwiki