Improper Encoding Vulnerability in Wikimedia Foundation MediaWiki Core
CVE-2025-32072
6.9MEDIUM
Key Information:
- Vendor
- The Wikimedia Foundation
- Status
- Mediawiki Core - Feed Utils
- Vendor
- CVE Published:
- 11 April 2025
Summary
An improper encoding or escaping of output vulnerability found in the Wikimedia Foundation's MediaWiki Core - Feed Utils can lead to WebView Injection attacks. This vulnerability affects versions 1.39 to 1.43 of the MediaWiki Core - Feed Utils, posing significant security risks if exploited. Attackers may inject malicious content into the application, impacting data integrity and user security. It is crucial to apply updates or mitigations provided by the vendor to safeguard against potential exploitation.
Affected Version(s)
Mediawiki Core - Feed Utils 1.39 <= 1.43
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lucas_Werkmeister_WMDE