- Description
- ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Special:ManageWiki/namespaces when using a page prefix (namespace name, which is the current namespace you are renaming) with an injection payload. This issue has been patched in commit f504ed8. A workaround for this vulnerability involves setting `$wgManageWiki['namespaces'] = false;`.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8
- Impact score
- 5.9
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-89
- Hype score
- Not currently trending
CVE-2025-32956 (CVSS:8.0, HIGH) is Awaiting Analysis. ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ..https://t.co/H1doQyx2Zg #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
26 Apr 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-32956 (CVSS:8.0, HIGH) is Awaiting Analysis. ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ..https://t.co/H1doQyx2Zg #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
25 Apr 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-32956 🔴 HIGH (8) 🏢 miraheze - ManageWiki 🏗️ < f504ed8 🔗 https://t.co/ozblXrhdVP 🔗 https://t.co/gLWW6IKg7k #CyberCron #VulnAlert #InfoSec https://t.co/Ntvl9ESEti
@cybercronai
22 Apr 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-32956 SQL Injection in ManageWiki Extension for MediaWiki During Namespace Renaming https://t.co/NI1JUJuzYf
@VulmonFeeds
21 Apr 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-32956 ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Speci… https://t.co/LHSaZoYqEQ
@CVEnew
21 Apr 2025
551 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes