VYPR

SemanticDrilldown

by MediaWiki

CVEs (2)

  • CVE-2022-29904CriApr 29, 2022
    risk 0.65cvss 9.8epss 0.17

    The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.

  • CVE-2022-4561LowDec 16, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in SemanticDrilldown Extension. Affected is the function printFilterLine of the file includes/specials/SDBrowseDataPage.php of the component GET Parameter Handler. The manipulation of the argument value leads to cross site…