Admin API Module Vulnerability in QuizGame Extension for MediaWiki
CVE-2022-29906
9.8CRITICAL
What is CVE-2022-29906?
The admin API module in the QuizGame extension for MediaWiki prior to version 1.37.2 lacks proper checks for the quizadmin user role. This omission allows unauthorized users to potentially exploit the API, bypassing intended user permissions and accessing sensitive administrative functionalities. Users are advised to update to a secure version to mitigate risks associated with this vulnerability.
