An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://phabricator.wikimedia.org/T345680 | vendor advisory issue tracking |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SportsTeams/+/959699/ | vendor advisory issue tracking |