SQL Injection Vulnerability in MediaWiki Cargo Extension by Wikimedia Foundation
CVE-2025-62655
2.1LOW
What is CVE-2025-62655?
The MediaWiki Cargo extension from Wikimedia Foundation contains a vulnerability that allows for SQL Injection due to improper neutralization of special elements used in SQL commands. This flaw could let attackers manipulate queries executed against the database, potentially leading to unauthorized access and data leakage. Users and administrators of affected versions 1.39, 1.43, and 1.44 are advised to evaluate the risk and implement necessary mitigation strategies to protect sensitive data.
Affected Version(s)
MediaWiki Cargo extension 1.39
MediaWiki Cargo extension 1.43
MediaWiki Cargo extension 1.44