CyberRota Analysis
AI-GeneratedThe ExternalData Extension of MediaWiki, prior to version 3.7, is vulnerable to OS Command Injection due to improper handling of special elements. This critical vulnerability allows attackers to execute arbitrary commands on the server, potentially compromising the entire system. Organizations using affected versions of MediaWiki should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.