CVE-2025-62658: SQL injection in WatchAnalytics through Special:ClearPendingReviews
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalytics extension allows SQL Injection.This issue affects MediaWiki WatchAnalytics extension: 1.43, 1.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62658?
The severity of CVE-2025-62658 is classified as high due to its potential for exploiting SQL Injection vulnerabilities.
How do I fix CVE-2025-62658?
To fix CVE-2025-62658, update the MediaWiki WatchAnalytics extension to the latest version that addresses the vulnerability.
Which versions of the MediaWiki WatchAnalytics extension are affected by CVE-2025-62658?
CVE-2025-62658 affects MediaWiki WatchAnalytics extension versions 1.43 and 1.44.
What type of vulnerability is CVE-2025-62658?
CVE-2025-62658 is an SQL Injection vulnerability caused by improper neutralization of special elements used in SQL commands.
Who is affected by CVE-2025-62658?
Users and organizations running the affected versions of the Wikimedia Foundation MediaWiki WatchAnalytics extension are at risk from CVE-2025-62658.