PT-2026-99126 · Mediawiki · Externaldata Extension
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Mediawiki - ExternalData Extension versions prior to 3.7
Description
An OS Command Injection issue exists in the ExternalData extension, which allows unauthenticated remote code execution through wikitext. This occurs due to the improper neutralization of special elements used in an OS command.
Recommendations
Update Mediawiki - ExternalData Extension to version 3.7 or later.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Externaldata Extension