MediaWiki SecurePoll Extension Cross-Site Request Forgery Vulnerability in Page Management Scripts
Vulnerability
A cross-site request forgery (CSRF) vulnerability has been identified in the MediaWiki SecurePoll extension, specifically in versions 1.39.X prior to 1.39.13, 1.42.X prior to 1.42.7, and 1.43.X prior to 1.43.2. The vulnerability arises because the ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() scripts do not properly validate request methods or CSRF tokens. This lack of validation enables attackers to invoke sensitive actions, provided that an admin visits a malicious site.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of sensitive actions by an admin user.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
