CVE-2025-67646

Source
https://cve.org/CVERecord?id=CVE-2025-67646
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-67646.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-67646
Aliases
  • GHSA-j24f-hw6w-cq78
Published
2025-12-10T23:45:02.225Z
Modified
2026-03-14T12:45:56.405307Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
TableProgressTracking's missing CSRF protection allows unauthorized state changes
Details

TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would trigger unintended authenticated actions through the victim's browser. Due to the lack of token validation, an attacker can delete or track progress against tables. This issue is patched in version 1.2.1 of the extension.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67646.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-352"
    ]
}
References

Affected packages

Git / github.com/telepedia/tableprogresstracking

Affected ranges

Type
GIT
Repo
https://github.com/telepedia/tableprogresstracking
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "the"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-67646.json"