CNNVD-202510-2442 Information

CNNVD ID

CNNVD-202510-2442

CVE-2025-62655

  • CNNVD Published: 2025-10-17

Description (Chinese)

Mediawiki - Cargo Extension是Mediawiki开源的一个查询和存储数据的插件。 Mediawiki - Cargo Extension 1.39版本、1.43版本和1.44版本存在安全漏洞,该漏洞源于特殊元素中和不当,可能导致SQL注入攻击。

Description (English)

Mediawiki - Cargo Extension is a query and storage plugin for Mediawiki open source. Mediawiki-Cargo Extension 1.39, 1.43 and 1.44 have a security loophole, which stems from the incompetence of particular elements and could lead to an attack by SQL.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

维基媒体

Published

2025-10-17

Last Modified

2026-02-24

References

https://phabricator.wikimedia.org/T404016 https://access.redhat.com/security/cve/cve-2025-62655

Patch

https://phabricator.wikimedia.org/T404016

Share on: