Improper Input Validation in Wikimedia Foundation's MediaWiki Visual Data Extension
CVE-2025-32076

6.9MEDIUM

Key Information:

Vendor
CVE Published:
11 April 2025

Summary

An improper input validation vulnerability exists in the Visual Data Extension of Wikimedia's MediaWiki. This security flaw allows attackers to exploit the input handling mechanisms, potentially leading to Denial of Service (DoS) conditions via HTTP requests. The issue affects versions 1.39 to 1.43, allowing malicious users to disrupt service availability significantly.

Affected Version(s)

Mediawiki - Visual Data Extension 1.39 <= 1.43

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bawolff
Thomas-topway-it
.
CVE-2025-32076 : Improper Input Validation in Wikimedia Foundation's MediaWiki Visual Data Extension | SecurityVulnerability.io