CVE-2022-29904: SQL Injection
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '' constraints.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29904?
CVE-2022-29904 has a high severity rating due to its nature as an SQL injection vulnerability that can compromise database security.
How do I fix CVE-2022-29904?
To fix CVE-2022-29904, update the SemanticDrilldown extension to a version after e688bdba6434591b5dff689a45e4d53459954773.
What systems are affected by CVE-2022-29904?
CVE-2022-29904 affects MediaWiki versions up to and including 1.37.2 that have the SemanticDrilldown extension installed.
What type of vulnerability is CVE-2022-29904?
CVE-2022-29904 is classified as an SQL injection vulnerability, allowing attackers to execute arbitrary SQL commands.
Can CVE-2022-29904 lead to data leakage?
Yes, CVE-2022-29904 can lead to data leakage, unauthorized access to sensitive information, and potential data manipulation.