CVE Database
/

CVE-2025-53485

Back to search

CVE-2025-53485

Published: Jul 4, 2025

Modified: Jul 8, 2025

PUBLISHED

Description

SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

VendorProductVersions

Wikimedia Foundation

Mediawiki - SecurePoll extension

affected
1.39.x - < 1.39.13
affected
1.42.x - < 1.42.7
affected
1.43.x - < 1.43.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now