Critical Vulnerability Discovered in MediaWiki: CVE-2023-45362
A recently identified vulnerability, CVE-2023-45362, affects various versions of MediaWiki, an open-source wiki software used by numerous websites worldwide, including Wikipedia. This issue, classified as an information leak, has potential security implications for users running vulnerable versions of MediaWiki.
Impact and Severity
The Common Vulnerability Scoring System (CVSS) has assigned a base score of 4.3 (MEDIUM) to CVE-2023-45362 under CVSS v3.x. This score reflects the vulnerability's potential for unauthorized access to sensitive information.
Relevance to North East India and India
Given the widespread use of MediaWiki, it is likely that websites based in North East India and across India are also affected. It is crucial for these organizations to assess their MediaWiki versions and apply the necessary updates to mitigate the risk.
Vulnerable Software and Solutions
The affected versions of MediaWiki include those between 1.35.12 and 1.39.5, as well as 1.40.x before 1.40.1. Users are advised to upgrade their MediaWiki installations to the latest patched versions to address this vulnerability.
Timeline and Analysis
The vulnerability was first reported on November 3, 2023, and the National Vulnerability Database (NVD) published the associated CVE entry on the same day. Since then, several updates have been made to the CVE record, with the latest modification on April 11, 2025.
Implications and Future Considerations
CVE-2023-45362 underscores the importance of keeping software updated to ensure security and maintain the integrity of user data. As the digital landscape continues to evolve, it is essential for organizations to prioritize cybersecurity and stay informed about the latest vulnerabilities and their potential impacts.