MediaWiki Incorrect Authorization Vulnerability - CVE-2023-22945 - Vulnerability Database

MediaWiki Incorrect Authorization Vulnerability - CVE-2023-22945

Medium
Reference: CVE-2023-22945
Title: MediaWiki Incorrect Authorization Vulnerability
Overview:

In the GrowthExperiments extension for MediaWiki through 1.39 the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.