CVE Explorer
CVE-2025-67646
TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would trigger unintended authenticated actions through the victim's browser. Due to the lack of token validation, an attacker can delete or track progress against tables. This issue is patc
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"TableProgressTracking","vendor":"Telepedia","versions":[{"status":"affected","version":"< 1.2.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7b84a00bba968e455bae54a15e6beb3ea968e8b7e3092c39222b54f9ba18909b · sha256:b2d6dded7392818d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7b84a00bba968e455bae54a15e6beb3ea968e8b7e3092c39222b54f9ba18909b · sha256:b2d6dded7392818d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352: Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7b84a00bba968e455bae54a15e6beb3ea968e8b7e3092c39222b54f9ba18909b · sha256:b2d6dded7392818d… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/Telepedia/TableProgressTracking/commit/e2aa8c4b3bb78989c6fe39070a95a26d22b91c94","tags":["x_refsource_MISC"],"url":"https://github.com/Telepedia/TableProgressTracking/commit/e2aa8c4b3bb78989c6fe39070a95a26d22b91c94"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7b84a00bba968e455bae54a15e6beb3ea968e8b7e3092c39222b54f9ba18909b · sha256:b2d6dded7392818d… · /containers/cna/references/1
{"name":"https://github.com/Telepedia/TableProgressTracking/security/advisories/GHSA-j24f-hw6w-cq78","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Telepedia/TableProgressTracking/security/advisories/GHSA-j24f-hw6w-cq78"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7b84a00bba968e455bae54a15e6beb3ea968e8b7e3092c39222b54f9ba18909b · sha256:b2d6dded7392818d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.