GHSA-jr78-w6w5-m8f8: Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-on
VULNsource · GTH
HIGHHigh-risk vulnerability — CVSS 7.3
### Summary The `api.php?action=smwtask` API module performs no authorization check. The equivalent maintenance interface in the web UI (`Special:SMWAdmin`) requires the `smw-admin` right, but the API module that backs several of the same operations enforces nothing. An unauthenticated visitor can therefore retrieve internal Semantic MediaWiki database statistics and reach state-changing maintenance operations that are intended to be administrator-only. …
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected