{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/semantic-mediawiki-3.1.0---7.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Semantic MediaWiki (3.0.0-7.2.1)","Semantic MediaWiki (3.1.0 - 7.0.0)"],"_cs_severities":["high"],"_cs_tags":["api-security","broken-access-control","webserver","web-security","xss","cms"],"_cs_type":"threat","_cs_vendors":["Semantic MediaWiki","SemanticMediaWiki"],"content_html":"\u003cp\u003eSemantic MediaWiki versions 3.0.0 through 7.2.1 contain a critical authorization vulnerability in the \u003ccode\u003esmwtask\u003c/code\u003e API module. The module implements a \u003ccode\u003eneedsToken('csrf')\u003c/code\u003e check, but because MediaWiki provides a fixed, public CSRF token (\u003ccode\u003e+\\\u003c/code\u003e) to anonymous users, this check fails to prevent unauthenticated access. Consequently, an attacker can invoke administrative tasks that are otherwise restricted to users with the \u003ccode\u003esmw-admin\u003c/code\u003e right via the \u003ccode\u003eSpecial:SMWAdmin\u003c/code\u003e web interface. The vulnerability allows attackers to query internal database statistics, enumerate object IDs, inject arbitrary maintenance jobs (such as fulltext search rebuilds or entity disposal), and force synchronous job execution, leading to both information disclosure and potential data integrity loss.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a request to \u003ccode\u003eapi.php?action=query\u0026amp;meta=tokens\u0026amp;type=csrf\u003c/code\u003e to retrieve the anonymous session CSRF token.\u003c/li\u003e\n\u003cli\u003eThe server responds with the default public token value \u003ccode\u003e+\\\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker constructs an HTTP POST request to \u003ccode\u003eapi.php?action=smwtask\u003c/code\u003e using the \u003ccode\u003e+\\\u003c/code\u003e token to satisfy the CSRF check.\u003c/li\u003e\n\u003cli\u003eAttacker calls \u003ccode\u003etable-statistics\u003c/code\u003e via the \u003ccode\u003etask\u003c/code\u003e parameter to enumerate internal object-ID spaces and database metrics.\u003c/li\u003e\n\u003cli\u003eAttacker calls \u003ccode\u003einsert-job\u003c/code\u003e to enqueue administrative tasks, such as \u003ccode\u003esmw.entityIdDisposer\u003c/code\u003e or \u003ccode\u003esmw.fulltextSearchTableRebuild\u003c/code\u003e, targeting specific wiki identifiers.\u003c/li\u003e\n\u003cli\u003eAttacker calls \u003ccode\u003erun-joblist\u003c/code\u003e with a serialized parameters object to force synchronous execution of the injected maintenance jobs.\u003c/li\u003e\n\u003cli\u003eThe application executes the requested administrative jobs with the privileges of the system backend, resulting in unauthorized data modification or performance degradation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated actors to bypass access controls intended for administrators. Observed consequences include unauthorized disclosure of database internal structures and statistics, resource exhaustion via forced synchronous job execution, and the modification or deletion of semantic data entities. The severity of the impact scales with the size of the wiki's semantic store and the criticality of the targeted maintenance operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate remediation of affected Semantic MediaWiki instances by upgrading to version 7.3.0 or later. If an immediate upgrade is not feasible, implement a hotfix in the site's \u003ccode\u003eLocalSettings.php\u003c/code\u003e to unregister the vulnerable API module:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-php\" data-lang=\"php\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nv\"\u003e$wgExtensionFunctions\u003c/span\u003e\u003cspan class=\"p\"\u003e[]\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"k\"\u003estatic\u003c/span\u003e \u003cspan class=\"k\"\u003efunction\u003c/span\u003e \u003cspan class=\"p\"\u003e()\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e \u003cspan class=\"nx\"\u003eunset\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e \u003cspan class=\"nv\"\u003e$GLOBALS\u003c/span\u003e\u003cspan class=\"p\"\u003e[\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;wgAPIModules\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e][\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;smwtask\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e]\u003c/span\u003e \u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e};\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eDeploy detection rules to monitor for anomalous POST requests to the \u003ccode\u003eapi.php\u003c/code\u003e endpoint containing \u003ccode\u003eaction=smwtask\u003c/code\u003e and verify the identity of the requesting user.\u003c/p\u003e\n","date_modified":"2026-09-18T19:52:12Z","date_published":"2026-09-18T19:52:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-smwtask-auth-bypass/","summary":"The Semantic MediaWiki smwtask API module fails to enforce authorization, enabling unauthenticated remote attackers to perform sensitive information disclosure, queue administrative maintenance jobs, and manipulate stored semantic data.","title":"Unauthenticated Administrative Access in Semantic MediaWiki smwtask API","url":"https://feed.craftedsignal.io/briefs/2026-09-smwtask-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Semantic MediaWiki (3.1.0 - 7.0.0)","version":"https://jsonfeed.org/version/1.1"}