Impact
This CVE documents a CSRF vulnerability in the MediaWiki RedirectManager extension that allows an attacker to forge requests from an authenticated user. The weakness is identified as CWE‑352, and the description does not specify which specific operations could be performed; it only indicates that state‑changing actions handled by the extension could be forced. The CVSS score of 6.9 indicates moderate risk, while the EPSS score of less than 1 % and the absence of a KEV listing suggest a low probability of widespread exploitation.
Affected Systems
The vulnerability affects all installations of the MediaWiki RedirectManager extension with a version number older than 1.3.3. Any MediaWiki instance running a pre‑1.3.3 release of this extension is potentially exposed. The product is maintained by the Wikimedia Foundation.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability carries moderate severity. The EPSS score below 1 % indicates a very low prevalence of exploit use, and the lack of a KEV listing signifies that there are no known widely‑used exploits at this time. The attack requires a victim who is logged into the MediaWiki site and an attacker who can craft a request that triggers a state‑changing operation handled by the extension. Because the flaw is a CSRF and does not enable remote code execution or privilege escalation, the impact is limited to unauthorized content changes within the context of the victim’s privileges.
OpenCVE Enrichment