SQL Injection Vulnerability in MediaWiki Cargo Extension by Wikimedia Foundation
CVE-2025-62655

2.1LOW

Key Information:

Vendor
CVE Published:
17 October 2025

What is CVE-2025-62655?

The MediaWiki Cargo extension from Wikimedia Foundation contains a vulnerability that allows for SQL Injection due to improper neutralization of special elements used in SQL commands. This flaw could let attackers manipulate queries executed against the database, potentially leading to unauthorized access and data leakage. Users and administrators of affected versions 1.39, 1.43, and 1.44 are advised to evaluate the risk and implement necessary mitigation strategies to protect sensitive data.

Affected Version(s)

MediaWiki Cargo extension 1.39

MediaWiki Cargo extension 1.43

MediaWiki Cargo extension 1.44

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
.
CVE-2025-62655 : SQL Injection Vulnerability in MediaWiki Cargo Extension by Wikimedia Foundation