TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would trigger unintended authenticated actions through the victim's browser. Due to the lack of token validation, an attacker can delete or track progress against tables. This issue is patched in version 1.2.1 of the extension.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Telepedia
Telepedia tableprogresstracking
Vendors & Products Telepedia
Telepedia tableprogresstracking

Thu, 11 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
Description TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would trigger unintended authenticated actions through the victim's browser. Due to the lack of token validation, an attacker can delete or track progress against tables. This issue is patched in version 1.2.1 of the extension.
Title TableProgressTracking's missing CSRF protection allows unauthorized state changes
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-11T18:07:35.301Z

Reserved: 2025-12-09T18:36:41.331Z

Link: CVE-2025-67646

cve-icon Vulnrichment

Updated: 2025-12-11T18:07:29.266Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-11T00:16:23.393

Modified: 2025-12-12T15:18:13.390

Link: CVE-2025-67646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-11T21:37:53Z

Weaknesses