CVE-2023-22945

MEDIUM

MediaWiki GrowthExperiments < 1.39.0 - Incorrect Authorization in Mentor List Management

Title source: llm
STIX 2.1

Description

In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.

Scores

CVSS v3 4.3
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
fedoraproject/fedora 37
mediawiki/mediawiki < 1.39.0
Published Jan 11, 2023
Tracked Since Feb 18, 2026