CVE-2023-22945: Fedoraproject Fedora
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.
Affected products
- Fedoraproject Fedora: version 37 only
- Mediawiki Mediawiki: up to and including 1.39.0
Published 2023-01-11. Last modified 2026-06-17.