Improper Input Validation in Wikimedia Foundation's MediaWiki Visual Data Extension
CVE-2025-32076
6.9MEDIUM
Summary
An improper input validation vulnerability exists in the Visual Data Extension of Wikimedia's MediaWiki. This security flaw allows attackers to exploit the input handling mechanisms, potentially leading to Denial of Service (DoS) conditions via HTTP requests. The issue affects versions 1.39 to 1.43, allowing malicious users to disrupt service availability significantly.
Affected Version(s)
Mediawiki - Visual Data Extension 1.39 <= 1.43
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bawolff
Thomas-topway-it