cve/2025/CVE-2025-54865.md
2025-09-29 21:09:30 +02:00

920 B

CVE-2025-54865

Description

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.

POC

Reference

Github

No PoCs found on GitHub currently.