CVE-2025-67476

N/A Unknown

📋 TL;DR

This vulnerability in MediaWiki's ImportableOldRevisionImporter.php allows attackers to potentially execute unauthorized actions during content imports. It affects all MediaWiki installations running vulnerable versions, particularly those using import functionality. The exact nature isn't publicly detailed but involves improper handling of imported content.

💻 Affected Systems

Products:
  • MediaWiki
Versions: MediaWiki versions before 1.44.3 and 1.45.1
Operating Systems: All
Default Config Vulnerable: ⚠️ Yes
Notes: Affects systems with import functionality enabled

⚠️ Risk & Real-World Impact

🔴

Worst Case

Remote code execution or privilege escalation through malicious import data

🟠

Likely Case

Unauthorized content modification or data manipulation during imports

🟢

If Mitigated

Limited impact if import functionality is disabled or restricted

🌐 Internet-Facing: HIGH
🏢 Internal Only: MEDIUM

🎯 Exploit Status

Public PoC: ✅ No
Weaponized: UNKNOWN
Unauthenticated Exploit: ✅ No
Complexity: MEDIUM

Requires import access; details limited in public disclosure

🛠️ Fix & Mitigation

✅ Official Fix

Patch Version: 1.44.3 or 1.45.1

Vendor Advisory: https://phabricator.wikimedia.org/T405859

Restart Required: No

Instructions:

1. Backup your MediaWiki installation. 2. Update MediaWiki to version 1.44.3 or 1.45.1. 3. Verify the update completed successfully.

🔧 Temporary Workarounds

Disable Import Functionality

all

Temporarily disable the Special:Import page to prevent exploitation

Add to LocalSettings.php: $wgGroupPermissions['*']['import'] = false;
Add to LocalSettings.php: $wgGroupPermissions['user']['import'] = false;

🧯 If You Can't Patch

  • Restrict import permissions to trusted administrators only
  • Monitor import logs for suspicious activity

🔍 How to Verify

Check if Vulnerable:

Check MediaWiki version in includes/DefaultSettings.php or via Special:Version

Check Version:

grep 'wgVersion' includes/DefaultSettings.php

Verify Fix Applied:

Confirm version is 1.44.3 or 1.45.1 via Special:Version

📡 Detection & Monitoring

Log Indicators:

  • Unusual import activity from unexpected users
  • Failed import attempts with malformed data

Network Indicators:

  • HTTP requests to Special:Import with suspicious parameters

SIEM Query:

source="mediawiki.log" AND "Special:Import" AND (status="failed" OR user!="trusted_user")

🔗 References

📤 Share This