SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing.
This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Jul 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
Title | SecurePoll: Unauthorized access to SetTranslationHandler allows arbitrary text changes | |
Weaknesses | CWE-862 | |
References |
|

Status: PUBLISHED
Assigner: wikimedia-foundation
Published: 2025-07-04T17:39:36.272Z
Updated: 2025-07-04T17:44:31.423Z
Reserved: 2025-06-30T15:20:44.462Z
Link: CVE-2025-53485

No data.

Status : Received
Published: 2025-07-04T18:15:23.497
Modified: 2025-07-04T18:15:23.497
Link: CVE-2025-53485

No data.