CVE-2020-5302 - CVE House
Back to Database
Status published High CVE-2020-5302

unprivileged user can access priviledged action in MH-WikiBot

Vulnerability Description

MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access the steward commands on the IRC interface by impersonating the Nickname used by a privileged user as no check was made to see if they were logged in. The issue has been fixed in commit 23d9d5b0a59667a5d6816fdabb960b537a5f9ed1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5302

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

MH-WikiBot
Vulnerable Versions:
< commit 23d9d5b0a59667a5d6816fdabb960b537a5f9ed1

Timeline

Official Publish: April 7th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Weaknesses (CWE)