logo

CVE-2025-23081 mediawiki/data-transfer

Package

Manager: composer
Name: mediawiki/data-transfer
Vulnerable Version: >=1.39.0 <1.39.11 || >=1.41.0 <1.41.3 || >=1.42.0 <1.42.2

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:U/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

EPSS: 0.00046 pctl0.13423

Details

Mediawiki - DataTransfer Extension Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS) Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects Mediawiki - DataTransfer Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.

Metadata

Created: 2025-01-14T18:32:00Z
Modified: 2025-01-14T20:07:51Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-c3h5-h73c-29hq/GHSA-c3h5-h73c-29hq.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-c3h5-h73c-29hq
Finding: F008
Auto approve: 1