Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.22.0:*:*:*:*:*:*:*", "matchCriteriaId": "DB117E2F-D4CD-4CED-BCEF-3C821A431F6A", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*", "matchCriteriaId": "B76902FB-9672-488B-9D9E-39B121DEC913", "versionEndIncluding": "1.19.9", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19:*:*:*:*:*:*:*", "matchCriteriaId": "93D7105D-3CF1-49FF-9F51-088C58F19003", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19:beta_1:*:*:*:*:*:*", "matchCriteriaId": "F647077F-52FD-460B-9511-85812A1447FD", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19:beta_2:*:*:*:*:*:*", "matchCriteriaId": "BB5A8AFF-EF0E-490C-8833-FF1071563979", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.0:*:*:*:*:*:*:*", "matchCriteriaId": "A7C29D44-2964-483F-B672-27B5CE471DA6", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.1:*:*:*:*:*:*:*", "matchCriteriaId": "172FEFE5-9900-49D0-9E14-2FA4A7912D23", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.2:*:*:*:*:*:*:*", "matchCriteriaId": "CA3205F5-3A29-4D45-AC95-83174F8969BB", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.3:*:*:*:*:*:*:*", "matchCriteriaId": "5547DA02-3BEC-4278-A714-25CCB820AA79", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.4:*:*:*:*:*:*:*", "matchCriteriaId": "A3E5609D-EC04-4088-9B61-ABDD256200F7", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.5:*:*:*:*:*:*:*", "matchCriteriaId": "B23B09BB-8F43-4D60-A37F-D8685584AF4B", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.6:*:*:*:*:*:*:*", "matchCriteriaId": "9A8A3F38-9A86-4346-9337-5C2A1DED37C0", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.7:*:*:*:*:*:*:*", "matchCriteriaId": "49CCC3B5-9BD4-40B4-AF1A-DF4B2A6DC12D", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.8:*:*:*:*:*:*:*", "matchCriteriaId": "36DA1112-69AB-408A-886E-F248516FDE11", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.21:*:*:*:*:*:*:*", "matchCriteriaId": "383CE1D8-7A58-4C24-8898-8C592F98EFCC", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.21.1:*:*:*:*:*:*:*", "matchCriteriaId": "3DA12531-818E-4AD7-A3E7-467604775416", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.21.2:*:*:*:*:*:*:*", "matchCriteriaId": "1E87AB00-90DD-4548-B23A-42673DDFD1D1", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.21.3:*:*:*:*:*:*:*", "matchCriteriaId": "01D8F235-2F1B-4198-A91E-B2723293AA36", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special pages in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow remote attackers to hijack the authentication of users for requests that have unspecified impact and vectors."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de CSRF en las p\u00e1ginas especiales (1) CreateProperty, (2) CreateTemplate, (3) CreateForm y (4) CreateClass en la extensi\u00f3n SemanticForms para MediaWiki anterior a 1.19.10, 1.2x anterior a 1.21.4 y 1.22.x anterior a 1.22.1 permiten a atacantes remotos secuestrar la autenticaci\u00f3n de usuarios para solicitudes que tienen impacto y vectores no especificados."}], "id": "CVE-2014-3455", "lastModified": "2025-04-12T10:46:40.837", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}]}, "published": "2014-05-12T14:55:07.290", "references": [{"source": "cve@mitre.org", "tags": ["Patch", "Vendor Advisory"], "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-January/000138.html"}, {"source": "cve@mitre.org", "url": "https://bugzilla.wikimedia.org/show_bug.cgi?id=57025"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch", "Vendor Advisory"], "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-January/000138.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.wikimedia.org/show_bug.cgi?id=57025"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-352"}], "source": "nvd@nist.gov", "type": "Primary"}]}