CVE-2025-54865: Tilesheets MediaWiki Extension is Vulnerable to Potential SQL Injection
Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54865?
CVE-2025-54865 is considered critical due to its potential to allow SQL injection, which can lead to data compromise.
How do I fix CVE-2025-54865?
To fix CVE-2025-54865, you should update the Tilesheets MediaWiki extension to the latest version where the vulnerability has been addressed.
What systems are affected by CVE-2025-54865?
CVE-2025-54865 affects the Tilesheets extension for MediaWiki, allowing for potential SQL code execution.
What is the impact of CVE-2025-54865?
The impact of CVE-2025-54865 includes unauthorized access to a database, data manipulation, and potentially complete control over the affected MediaWiki instance.
Is there a workaround for CVE-2025-54865 until a fix is released?
As of now, there is no confirmed workaround for CVE-2025-54865, and it is recommended to restrict access to the affected extension.