CVE-2025-32956
CVSS 3.1 Score 8 of 10 (high)
Details
Published Apr 21, 2025
Updated: May 12, 2025
CWE ID 89
Summary
CVE-2025-32956 is a vulnerability affecting ManageWiki, a MediaWiki extension. Versions of the software prior to commit f504ed8 contain a SQL injection weakness. This vulnerability can be exploited when renaming a namespace using a page prefix with an injection payload in the Special:ManageWiki/namespaces interface. The issue has been rectified in commit f504ed8. A temporary workaround for this vulnerability involves disabling the ManageWiki namespaces functionality by setting `$wgManageWiki['namespaces'] = false;`.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.