Authentication Bypass Using an Alternate Path or Channel in CreateWiki
Vulnerability Description
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available in the `master` branch of CreateWiki's GitHub repository.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24813
Credits & Attribution
No credits recorded in the NVD database.
References
More from miraheze
View All →Affected Vendor
miraheze
View all reports →