PT-2025-42668 · WordPress+1 · Cargo+1

Somerandomdeveloper

·

Published

2025-10-17

·

Updated

2025-10-18

·

CVE-2025-62655

CVSS v4.0

2.1

Low

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions MediaWiki Cargo extension versions 1.39, 1.43, and 1.44
Description A flaw exists in the MediaWiki Cargo extension that allows for SQL Injection. This occurs due to improper neutralization of special elements within SQL commands. The issue could potentially allow an attacker to manipulate database queries.
Recommendations Update to a newer version of the MediaWiki Cargo extension that addresses this issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62655

Affected Products

Cargo
Mediawiki