Improper Input Validation in Mediawiki AJAX Poll Extension by Wikimedia Foundation
CVE-2025-32070

10CRITICAL

Key Information:

Vendor
CVE Published:
11 April 2025

Summary

An improper input validation flaw in the AJAX Poll Extension of Mediawiki allows for Cross-Site Scripting (XSS) attacks. This vulnerability can be exploited by attackers to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions and data exposure. It affects versions 1.39 to 1.43, emphasizing the necessity for users to update to the latest release to mitigate any associated risks.

Affected Version(s)

Mediawiki - AJAX Poll Extension 1.39 <= 1.43

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BlankEclair
.