An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.
History

Thu, 19 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-10-09T00:00:00

Updated: 2024-09-19T17:58:01.047Z

Reserved: 2023-10-09T00:00:00

Link: CVE-2023-45370

cve-icon Vulnrichment

Updated: 2024-08-02T20:21:16.458Z

cve-icon NVD

Status : Modified

Published: 2023-10-09T06:15:10.470

Modified: 2024-09-19T18:35:05.060

Link: CVE-2023-45370

cve-icon Redhat

No data.