ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Special:ManageWiki/namespaces when using a page prefix (namespace name, which is the current namespace you are renaming) with an injection payload. This issue has been patched in commit f504ed8. A workaround for this vulnerability involves setting `$wgManageWiki['namespaces'] = false;`.
References
Configurations
No configuration.
History
23 Apr 2025, 14:08
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-21 21:15
Updated : 2025-04-23 14:08
NVD link : CVE-2025-32956
Mitre link : CVE-2025-32956
CVE.ORG link : CVE-2025-32956
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')