Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects MediaWiki Cargo extension: 1.39, 1.43, 1.44.
References
History

Mon, 20 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediawiki
Mediawiki mediawiki
Vendors & Products Mediawiki
Mediawiki mediawiki

Fri, 17 Oct 2025 23:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects MediaWiki Cargo extension: 1.39, 1.43, 1.44.
Title SQL injection in Cargo via Special:CargoExport
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published: 2025-10-17T22:46:28.849Z

Updated: 2025-10-20T18:41:36.265Z

Reserved: 2025-10-17T22:01:52.601Z

Link: CVE-2025-62655

cve-icon Vulnrichment

Updated: 2025-10-20T18:41:24.494Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-17T23:15:35.493

Modified: 2025-10-21T19:31:50.020

Link: CVE-2025-62655

cve-icon Redhat

No data.