Impact
Improper neutralization of special elements used in an SQL command in the Wikimedia Foundation MediaWiki Cargo Extension creates a classic SQL injection flaw described by CWE-89. The issue resides in the year-range filter supplied by Cargo queries, allowing attackers to inject arbitrary SQL that can read, modify, or delete data stored in the database, potentially compromising confidentiality, integrity, and availability.
Affected Systems
All releases of the MediaWiki Cargo Extension that precede MediaWiki 1.43.9, 1.44.6, or 1.45.4 are affected. Versions 1.43.9 or newer, 1.44.6 or newer, and 1.45.4 or newer, respectively, contain the patch and are not vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk, while the EPSS score of less than 1% points to a very low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the web interface where a user can supply a crafted year range in a Cargo query; if the user has sufficient permissions to execute queries, the injection can be performed.
OpenCVE Enrichment