CVE-2025-67479

Description

A flaw was found in Wikimedia Foundation MediaWiki and Cite. This vulnerability is associated with the software's parsing and sanitization functions, specifically within CoreParserFunctions.Php and Sanitizer.Php. While the exact method of exploitation and its consequences are not fully detailed, such issues can potentially lead to unexpected behavior or data processing within the application.

Statement

This vulnerability affects MediaWiki, allowing for the use of reserved data attributes through wikitext due to a flaw in the legacy parser's magic word replacement mechanism. This could enable unauthorized content manipulation within affected MediaWiki installations, specifically those distributed in Fedora.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Application Data

An attacker could modify sensitive data or program variables.

Integrity

Technical Impact: Execute Unauthorized Code or Commands

Other,Integrity

Technical Impact: Varies by Context; Alter Execution Logic

Frequently Asked Questions

Want to get errata notifications? Sign up here.