CVE-2026-58521 Details
Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.
A SQL injection vulnerability has been identified in the Wikimedia Foundation MediaWiki Cargo Extension, affecting versions prior to 1.43.9, 1.44.6, and 1.45.4. The vulnerability arises from improper sanitization of the year range filter in the Special:Drilldown feature, allowing malicious SQL commands to be injected and executed. This exploitation can lead to unauthorized access to user data, including user tokens, which can be used to take over accounts, bypassing two-factor authentication. Additionally, the vulnerability could be used to cause a denial-of-service by disrupting database operations with resource-intensive queries.
Users can update to MediaWiki Cargo Extension versions 1.43.9, 1.44.6, or 1.45.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://phabricator.wikimedia.org/T428274 | CISA-ADP | PatchVendor Advisory |
| https://gerrit.wikimedia.org/r/c/1298854 | wikimedia-foundation | Issue Tracking |
| https://phabricator.wikimedia.org/T428274 | wikimedia-foundation | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | wikimedia-foundation |
Affected Products
| Product | Versions |
|---|---|
| mediawiki cargo | < 3.9.1 |
CPE
Remediation
| |
| mediawiki mediawiki | < 1.43.9 >= 1.44.0, < 1.44.6 >= 1.45.0, < 1.45.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | Reanalysis | [email protected] |
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | wikimedia-foundation |