Improper Input Validation in Mediawiki AJAX Poll Extension by Wikimedia Foundation
CVE-2025-32070
10CRITICAL
Summary
An improper input validation flaw in the AJAX Poll Extension of Mediawiki allows for Cross-Site Scripting (XSS) attacks. This vulnerability can be exploited by attackers to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions and data exposure. It affects versions 1.39 to 1.43, emphasizing the necessity for users to update to the latest release to mitigate any associated risks.
Affected Version(s)
Mediawiki - AJAX Poll Extension 1.39 <= 1.43
References
CVSS V4
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
BlankEclair