PT-2026-95516 · Unknown · Semantic Mediawiki

CVE-2026-77609

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Semantic MediaWiki versions prior to 7.2.0
Description Special:URIResolver resolves its user-controlled subpage to a MediaWiki title and issues an HTTP 303 redirect to $title->getFullURL() without validating the resolved target. A crafted subpage can force the target to point off-host using an interwiki prefix, which redirects to a foreign wiki. Additionally, the resolved URL can embed user:pass@host credentials. This leads to an open redirect to an attacker-influenced host, which can be used for phishing attacks originating from a trusted wiki URL.
Recommendations Update Semantic MediaWiki to version 7.2.0.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77609
GHSA-HW3M-8J5X-94FF

Affected Products

Semantic Mediawiki