CVE-2025-62697: Improperly sanitized style parameter in LanguageSelector
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62697?
The severity of CVE-2025-62697 is categorized as a medium-level vulnerability due to potential code injection risks.
How do I fix CVE-2025-62697?
To fix CVE-2025-62697, upgrade the Mediawiki - LanguageSelector Extension to version 1.39 or later.
What causes CVE-2025-62697?
CVE-2025-62697 is caused by improper neutralization of special elements in output used by a downstream component, leading to code injection vulnerabilities.
Which versions are affected by CVE-2025-62697?
CVE-2025-62697 affects Mediawiki - LanguageSelector Extension from master before version 1.39.
Is CVE-2025-62697 a client-side or server-side issue?
CVE-2025-62697 is primarily a server-side vulnerability affecting how the Mediawiki - LanguageSelector Extension processes inputs.