CyberRota Analysis
AI-GeneratedThe EasyTimeline extension for MediaWiki is vulnerable to XML injection, specifically blind XPath injection, which could allow an attacker to manipulate XML data and potentially execute unauthorized actions. Users of affected versions (prior to 1.46.1, 1.45.5, and 1.43.10) should prioritize patching this vulnerability to mitigate the risk of data compromise and unauthorized access. Organizations utilizing this extension should assess their deployments and apply updates promptly to safeguard their systems.
Original NVD Description
XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.