CVE-2025-53485
Awaiting Analysis Awaiting Analysis - Queue
BaseFortify

Publication date: 2025-07-04

Last updated on: 2025-07-08

Assigner: wikimedia-foundation

Description
SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-04
Last Modified
2025-07-08
Generated
2026-05-07
AI Q&A
2025-07-04
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the SetTranslationHandler.php file of the MediaWiki SecurePoll extension. It does not properly verify that a user is an election admin before allowing changes to election-related translation text. As a result, any user, including unauthenticated ones, can modify this translation text. Although newer versions of MediaWiki partially address this issue, the validation check is still missing in the affected versions.


How can this vulnerability impact me? :

This vulnerability allows unauthorized users to change election-related translation text, which could lead to misinformation or manipulation of election content. This could undermine the integrity and trustworthiness of election-related information presented through the MediaWiki SecurePoll extension.


What immediate steps should I take to mitigate this vulnerability?

Update the MediaWiki SecurePoll extension to a fixed version: at least 1.39.13 if using 1.39.X, at least 1.42.7 if using 1.42.X, or at least 1.43.2 if using 1.43.X. Until then, restrict access to SetTranslationHandler.php to trusted election administrators only to prevent unauthorized changes to election-related translation text.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart