Impact
The vulnerability lies in the EasyTimeline component of the Wikimedia Foundation timeline extension, specifically affecting the files scripts/EasyTimeline.Pl and includes/Timeline.Php. It is classified as CWE-94, indicating a code injection weakness. The description does not detail the exact scope of the flaw, but the classification implies that if an attacker can influence input processed by these files, arbitrary PHP code could be executed. This inference is drawn from the nature of CWE-94 and is not explicitly stated in the advisory.
Affected Systems
The Wikimedia Foundation timeline extension versions released before 1.46.0, including the specific releases 1.45.4, 1.44.6, and 1.43.9, are vulnerable.
Risk and Exploitability
No CVSS score is provided. The EPSS score is less than 1%, indicating a low probability of real‑world exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the nature of a code injection flaw, it is inferred that an attacker could craft input that reaches the EasyTimeline component—such as through a user‑submitted field or a configuration value—and trigger the evaluation of that input, though the exact conditions for exploitation remain unspecified.
OpenCVE Enrichment