This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20087 | SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. |
Tue, 08 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 04 Jul 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
| Title | SecurePoll: Unauthorized access to SetTranslationHandler allows arbitrary text changes | |
| Weaknesses | CWE-862 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2025-07-08T17:38:04.023Z
Reserved: 2025-06-30T15:20:44.462Z
Link: CVE-2025-53485
Updated: 2025-07-07T19:44:57.703Z
Status : Deferred
Published: 2025-07-04T18:15:23.497
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-53485
No data.
OpenCVE Enrichment
No data.
EUVD