Description
Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
References
github.com/...sheets/security/advisories/GHSA-hqfr-7cm9-4h87
github.com/...sheets/security/advisories/GHSA-hqfr-7cm9-4h87
github.com/...756bab5c085b007d72c50/special/SheetManager.php