← Back

CVE-2014-3455

nvd nist
Published: May 12, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special pages in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow remote attackers to hijack the authentication of users for requests that have unspecified impact and vectors.

Affected (18)

Products: Mediawiki: Mediawiki
1 product
Mediawiki
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.22.0
Configuration B
13 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Up to 1.19.9
Version 1.19.0
Version 1.19.1
Version 1.19.2
Version 1.19.3
Version 1.19.4
Version 1.19.5
Version 1.19.6
Version 1.19.7
Version 1.19.8
Version 1.19
Version 1.19 beta_1
Version 1.19 beta_2
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Version 1.21.1
Version 1.21.2
Version 1.21.3
Version 1.21

References (4)

Timeline

No history available yet.