THREAT OPS › Threat News › [GHSA] GHSA-jr78-w6w5-m8f8 (high) — Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
[GHSA] GHSA-jr78-w6w5-m8f8 (high) — Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
GHSA-jr78-w6w5-m8f8 Severity: high CVE: None
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
### Summary
The `api.php?action=smwtask` API module performs no authorization check. The equivalent maintenance interface in the web UI (`Special:SMWAdmin`) requires the `smw-admin` right, but the API module that backs se
Indicators of compromise
- https://HOST/api.php?action=query&meta=tokens&type=csrf&format=jsonurl
- https://HOST/api.phpurl
Original source: https://github.com/advisories/GHSA-jr78-w6w5-m8f8