PT-2025-16135 · Unknown+1 · Wikidata Extension+1

Lucas_Werkmeister_Wmde

·

Published

2025-04-11

·

Updated

2025-07-07

·

CVE-2025-32071

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mediawiki - Wikidata Extension versions 1.39 through 1.43
Description: The issue is related to improper input validation in the Mediawiki - Wikidata Extension, allowing Cross-Site Scripting (XSS) from the widthheight message via the ImageHandler::getDimensionsString() function.
Recommendations: For versions 1.39 through 1.43, consider disabling the ImageHandler::getDimensionsString() function as a temporary workaround until a patch is available. Restrict access to the widthheight message in the affected API endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-32071

Affected Products

Mediawiki
Wikidata Extension