Impact
The Mediawiki UrlShortener Extension contains an open redirect flaw (CWE-601) that allows a user-supplied URL to bypass any host validation. An attacker can supply a malicious target URL and trick users or browsers into loading an untrusted site, enabling phishing or cross-site attacks such as Cross‑Site Flashing. This flaw exists in all releases before 1.43.9, 1.44.6 and 1.45.4.
Affected Systems
The vulnerability affects the Wikimedia Foundation’s Mediawiki UrlShortener Extension for any version released before 1.43.9, 1.44.6, or 1.45.4.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker does not need authentication; the redirect is driven solely by a user‑supplied URL parameter. The likely attack vector is remote: an attacker can construct a malicious redirect link and deliver it through phishing emails, social engineering, or embedding it in a webpage to lure users onto malicious sites or induce harmful content execution.
OpenCVE Enrichment