Impact
The vulnerability is an unauthenticated SQL injection in the UserPageViewTracker extension of MediaWiki. Attackers can manipulate the filterusers and ignoreusers query parameters to inject arbitrary SQL code into backend queries, which can lead to extraction or modification of database contents. This flaw exposes sensitive data and can compromise the integrity of the system.
Affected Systems
The flaw impacts versions of the MediaWiki UserPageViewTracker extension that are earlier than 1.46.1, including 1.45.5 and 1.43.10, when distributed by the Wikimedia Foundation. Administrators running these legacy extensions are at risk.
Risk and Exploitability
No EPSS score is published and the vulnerability is not listed in the CISA KEV catalog. However, the combination of unauthenticated access and injection indicates that exploitation is technically feasible through simple web requests without special privileges. The absence of countermeasures in the affected code means the risk is moderate to high for applications exposed to the public internet.
OpenCVE Enrichment