Improper Encoding Vulnerability in Wikimedia Foundation MediaWiki Core
CVE-2025-32072

6.9MEDIUM

Key Information:

Vendor
The Wikimedia Foundation
Status
Mediawiki Core - Feed Utils
Vendor
CVE Published:
11 April 2025

Summary

An improper encoding or escaping of output vulnerability found in the Wikimedia Foundation's MediaWiki Core - Feed Utils can lead to WebView Injection attacks. This vulnerability affects versions 1.39 to 1.43 of the MediaWiki Core - Feed Utils, posing significant security risks if exploited. Attackers may inject malicious content into the application, impacting data integrity and user security. It is crucial to apply updates or mitigations provided by the vendor to safeguard against potential exploitation.

Affected Version(s)

Mediawiki Core - Feed Utils 1.39 <= 1.43

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucas_Werkmeister_WMDE
.