Improper Input Validation in Wikimedia Foundation's Mediawiki - GrowthExperiments
CVE-2025-32079

10CRITICAL

Key Information:

Vendor
CVE Published:
11 April 2025

Summary

An improper input validation vulnerability exists in the Wikimedia Foundation's Mediawiki - GrowthExperiments extension, which can potentially lead to HTTP Denial of Service (DoS) attacks. This vulnerability is present in versions 1.39 through 1.43, making it crucial for users to update and secure their installations to prevent exploitation. Detailed discussions regarding this issue can be found in the associated references.

Affected Version(s)

Mediawiki - GrowthExperiments 1.39 <= 1.43

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Urbanecm_WMF
.
CVE-2025-32079 : Improper Input Validation in Wikimedia Foundation's Mediawiki - GrowthExperiments | SecurityVulnerability.io