Impact
The vulnerability is an SQL injection flaw, identified as CWE‑89, caused by the Cargo Extension’s Special:Drilldown page failing to properly neutralize special elements in SQL commands. This allows an attacker to inject arbitrary SQL, potentially enabling disclosure of confidential data or modification of database contents.
Affected Systems
The MediaWiki Cargo Extension provided by the Wikimedia Foundation is affected. All releases prior to 1.43.9, 1.44.6, and 1.45.4 are vulnerable, meaning users running any earlier version cannot rely on the extension to safely handle input to the Special:Drilldown page.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. An EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is web‑based, occurring through the Special:Drilldown page with crafted parameters; the flaw can be triggered without authentication if the page is publicly accessible or requires only limited privileges if access is restricted.
OpenCVE Enrichment