SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing.




This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 08 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 18:00:00 +0000

Type Values Removed Values Added
Description SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Title SecurePoll: Unauthorized access to SetTranslationHandler allows arbitrary text changes
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2025-07-08T17:38:04.023Z

Reserved: 2025-06-30T15:20:44.462Z

Link: CVE-2025-53485

cve-icon Vulnrichment

Updated: 2025-07-07T19:44:57.703Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-04T18:15:23.497

Modified: 2025-07-08T18:15:41.277

Link: CVE-2025-53485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.