PT-2025-29123 · Mediawiki+1 · Mediawiki+1

Somemwdev

·

Published

2025-07-10

·

Updated

2025-07-15

·

CVE-2025-53371

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions: DiscordNotifications extension for MediaWiki (affected versions not specified)
Description: The DiscordNotifications extension for MediaWiki allows sending requests to arbitrary URLs set via configuration variables $wgDiscordIncomingWebhookUrl and $wgDiscordAdditionalIncomingWebhookUrls. This can lead to a denial-of-service (DOS) attack by causing the server to read large files. Server-Side Request Forgery (SSRF) is also possible if internal, unprotected APIs are accessible via HTTP POST requests, potentially leading to Remote Code Execution (RCE).
Recommendations: Update to a version containing commit 1f20d850cbcce5b15951c7c6127b87b927a5415e.

Exploit

Fix

Resource Exhaustion

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-53371
GHSA-GVFX-P3H5-QF65

Affected Products

Discordnotifications
Mediawiki