Impact
The vulnerability, an Improper Neutralization of Input Terminators flaw, lets blocked users bypass authentication controls and create or edit WikiLambda objects. As a result, users who should be denied access can modify or add protected content, compromising the integrity of the WikiLambda data. This is a classic authentication bypass scenario identified as CWE‑288.
Affected Systems
The issue affects MediaWiki’s WikiLambda Extension for all releases prior to 1.43.9, 1.44.6, and 1.45.4. The affected environment is the Wikimedia Foundation’s MediaWiki platform where the WikiLambda feature is enabled.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Because the EPSS score is <1%, exploitation likelihood is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack beyond the normal authentication mechanism are noted in the description, so the exploit is expected to be straightforward for an attacker who can gain blocked status or impersonate a blocked account.
OpenCVE Enrichment