CVE 8.8 HIGH

Improperly sanitized style parameter in LanguageSelector_CVE-2025-62697

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L

Description

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before 1.39.

AI Analysis

Code Injection vulnerability in Mediawiki - LanguageSelector Extension due to improper sanitization of style parameter

Basic Information

ID CVE-2025-62697
Source wikimedia-foundation
Published Oct 20, 2025 at 19:27
Modified Oct 20, 2025 at 19:38

Affected Product

Vendor The Wikimedia Foundation
Product Mediawiki - LanguageSelector Extension
Version master
Affected Versions The Wikimedia Foundation Mediawiki - LanguageSelector Extension master

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor The Wikimedia Foundation
Product Mediawiki - LanguageSelector Extension
Version master

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.