First published: Fri Apr 11 2025(Updated: )
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.
Credit: c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia Foundation Mediawiki - Wikidata Extension | >=1.39<=1.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32071 has been classified as a moderate severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2025-32071, update the Mediawiki - Wikidata Extension to a version later than 1.43.
CVE-2025-32071 is an improper input validation vulnerability allowing Cross-Site Scripting (XSS) from the widthheight message.
CVE-2025-32071 affects Mediawiki - Wikidata Extension versions from 1.39 through 1.43.
Yes, CVE-2025-32071 specifically affects the Wikimedia Foundation's Mediawiki - Wikidata Extension.