Description
ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Special:ManageWiki/namespaces when using a page prefix (namespace name, which is the current namespace you are renaming) with an injection payload. This issue has been patched in commit f504ed8. A workaround for this vulnerability involves setting `$wgManageWiki['namespaces'] = false;`.
Published: 2025-04-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14321 ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Special:ManageWiki/namespaces when using a page prefix (namespace name, which is the current namespace you are renaming) with an injection payload. This issue has been patched in commit f504ed8. A workaround for this vulnerability involves setting `$wgManageWiki['namespaces'] = false;`.
History

Fri, 19 Sep 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Miraheze
Miraheze managewiki
CPEs cpe:2.3:a:miraheze:managewiki:*:*:*:*:*:*:*:*
Vendors & Products Miraheze
Miraheze managewiki

Mon, 12 May 2025 16:45:00 +0000


Tue, 22 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Apr 2025 21:00:00 +0000

Type Values Removed Values Added
Description ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Special:ManageWiki/namespaces when using a page prefix (namespace name, which is the current namespace you are renaming) with an injection payload. This issue has been patched in commit f504ed8. A workaround for this vulnerability involves setting `$wgManageWiki['namespaces'] = false;`.
Title ManageWiki has SQL injection vulnerability in NamespaceMigrationJob
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Miraheze Managewiki
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-05-12T15:40:28.138Z

Reserved: 2025-04-14T21:47:11.452Z

Link: CVE-2025-32956

cve-icon Vulnrichment

Updated: 2025-05-12T15:40:28.138Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-21T21:15:20.647

Modified: 2025-09-19T15:47:40.820

Link: CVE-2025-32956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses