PT-2022-18961 · Mediawiki+1 · Securepoll Extension+2

Published

2022-04-30

·

Updated

2024-08-20

·

CVE-2022-28323

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.37.2
Description An issue was discovered in the SecurePoll extension of MediaWiki, allowing a leak because sorting by timestamp is supported.
Recommendations For MediaWiki versions through 1.37.2, consider disabling the sorting by timestamp feature in the SecurePoll extension as a temporary workaround until a patch is available.

Fix

Related Identifiers

ALT-PU-2022-3361
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2022-28323
CVE-2022-28323

Affected Products

Alt Linux
Mediawiki
Securepoll Extension