Vulnerability CVE-2022-24813


Published: 2022-04-04

Description:
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available in the `master` branch of CreateWiki's GitHub repository.

Type:

CWE-287

(Improper Authentication)

 References:
https://github.com/miraheze/CreateWiki/security/advisories/GHSA-9xvw-w66v-prvg
https://github.com/miraheze/CreateWiki/commit/d0ae79843d689832ccac765d6b1721e668d99ab9
https://phabricator.miraheze.org/T9018

Copyright 2026, cxsecurity.com

 

Back to Top