CVE-2025-11175: DiscussionTools should use better regex
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Blowup.This issue affects Mediawiki - DiscussionTools Extension: 1.44, 1.43.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11175?
CVE-2025-11175 has a high severity rating due to its potential for exploitation through Regular Expression Exponential Blowup.
How do I fix CVE-2025-11175?
To fix CVE-2025-11175, upgrade the Mediawiki - DiscussionTools Extension to version 1.45 or later.
Which versions of the Mediawiki - DiscussionTools Extension are affected by CVE-2025-11175?
CVE-2025-11175 affects all versions of the Mediawiki - DiscussionTools Extension from 1.43 up to and including 1.44.
What type of vulnerability is CVE-2025-11175?
CVE-2025-11175 is categorized as an Expression Language Injection vulnerability.
Can CVE-2025-11175 lead to denial of service?
Yes, CVE-2025-11175 can potentially lead to denial of service due to Regular Expression Exponential Blowup.