Impact
The vulnerability is a deserialization flaw in the MediaWiki Wikibase extension, allowing an attacker to supply crafted serialized data that is processed without authentication. The flaw can be used to delete arbitrary files on the server or to execute arbitrary code found in non‑executable files, leading to loss of data integrity and service availability. This weakness is identified as CWE‑502, Deserialization of Untrusted Data.
Affected Systems
The Wikimedia Foundation’s MediaWiki Wikibase extension versions 1.43, 1.45, and 1.46 are affected. Any site running these versions of the extension is vulnerable and can be reached by unauthenticated users.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity that could lead to remote code execution or significant data loss. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and its ability to alter critical files make it readily exploitable. Attackers can target any public or internal instance of MediaWiki that accepts serialized entity input, potentially compromising the file system or the entire web application.
OpenCVE Enrichment