CVE-2022-24813
Dashboard / Vulnerabilities / CVE-2022-24813
Summary: Authentication Bypass Using an Alternate Path or Channel in CreateWiki
Details: CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available in the `master` branch of CreateWiki's GitHub repository.
References: https://phabricator.miraheze.org/T9018, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24813.json, https://github.com/miraheze/CreateWiki/security/advisories/GHSA-9xvw-w66v-prvg, https://nvd.nist.gov/vuln/detail/CVE-2022-24813, https://github.com/miraheze/CreateWiki/commit/d0ae79843d689832ccac765d6b1721e668d99ab9
Affected packages
Package
Name:
Purl:
