CVE-2025-43861

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2025-43861 is a vulnerability affecting the ManageWiki MediaWiki extension. Prior to patch 2f177dc, ManageWiki was susceptible to reflected and stored Cross-Site Scripting (XSS) attacks. An attacker, who must be a logged-in user, could manipulate a form field to introduce a malicious payload. Upon opening the "Review Changes" dialog, the payload would be rendered and executed within the victim's own session. This vulnerability has since been addressed and patched in commit 2f177dc.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share