CNNVD-202507-151 Information

CNNVD ID

CNNVD-202507-151

CVE-2025-53494

  • CNNVD Published: 2025-07-02

Description (Chinese)

Wikimedia Mediawiki - TwoColConflict Extension是Wikimedia基金会的一个编辑冲突解决扩展。 Wikimedia Mediawiki - TwoColConflict Extension存在安全漏洞,该漏洞源于输入中和不当,可能导致存储型跨站脚本攻击。以下版本受到影响:1.39.X至1.39.13之前版本、1.42.X至1.42.7之前版本和1.43.X至1.43.2之前版本。

Description (English)

Wikimedia Mediawiki - TwoColConflect Extension is an editorial conflict resolution extension of the Wikimedia Foundation. Wikimedia Mediawiki - TwoColConflect Extension has a security loophole, which stems from inappropriate input and may result in a storage-type cross-station script attack. The following versions were affected: pre-versions 1.39X to 1.39.13, pre-versions 1.42X to 1.42.7 and pre-versions 1.43.X to 1.43.2.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

维基媒体

Published

2025-07-02

Last Modified

2026-02-24

References

https://gerrit.wikimedia.org/r/c/mediawiki/extensions/TwoColConflict/+/1150011 https://phabricator.wikimedia.org/T394938

Patch

https://www.mediawiki.org/wiki/Special:ExtensionDistributor/TwoColConflict

Share on: