PT-2025-4811 · Mediawiki · Mediawiki

Blankeclair

·

Published

2025-01-14

·

Updated

2025-01-18

·

CVE-2025-23081

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mediawiki - DataTransfer Extension versions 1.39.X through 1.39.10 Mediawiki - DataTransfer Extension versions 1.41.X through 1.41.2 Mediawiki - DataTransfer Extension versions 1.42.X through 1.42.1
Description The issue affects the Mediawiki - DataTransfer Extension, allowing Cross Site Request Forgery and Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation.
Recommendations For versions 1.39.X through 1.39.10, update to version 1.39.11 or later. For versions 1.41.X through 1.41.2, update to version 1.41.3 or later. For versions 1.42.X through 1.42.1, update to version 1.42.2 or later.

Fix

XSS

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-23081
GHSA-C3H5-H73C-29HQ

Affected Products

Mediawiki