Impact
Improper neutralization of special elements in SQL commands within the MediaWiki Cargo Extension allows injection of arbitrary SQL (CWE-89) through a year-range filter in Cargo queries. Based on the description, it is inferred that an attacker could read, modify, or delete data in the underlying database, compromising confidentiality, integrity, and availability.
Affected Systems
All releases of the MediaWiki Cargo Extension preceding MediaWiki 1.43.9, 1.44.6, or 1.45.4 are affected. Versions 1.43.9 and later for MediaWiki 1.43.x, 1.44.6 and later for MediaWiki 1.44.x, and 1.45.4 and later for MediaWiki 1.45.x contain the fix.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while an EPSS score of less than 1% suggests a very low probability of current exploitation. The vulnerability is not listed in CISA KEV. Based on the way Cargo queries are processed, it is inferred that the attack vector would be via the web interface where a user supplies a crafted year range in a query.
OpenCVE Enrichment