PT-2025-4811 · Mediawiki · Mediawiki
Blankeclair
·
Published
2025-01-14
·
Updated
2025-01-18
·
CVE-2025-23081
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mediawiki - DataTransfer Extension versions 1.39.X through 1.39.10
Mediawiki - DataTransfer Extension versions 1.41.X through 1.41.2
Mediawiki - DataTransfer Extension versions 1.42.X through 1.42.1
Description
The issue affects the Mediawiki - DataTransfer Extension, allowing Cross Site Request Forgery and Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation.
Recommendations
For versions 1.39.X through 1.39.10, update to version 1.39.11 or later.
For versions 1.41.X through 1.41.2, update to version 1.41.3 or later.
For versions 1.42.X through 1.42.1, update to version 1.42.2 or later.
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mediawiki