Skip to main content

CVE-2025-54865: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in FTB-Gamepedia Tilesheets

High
VulnerabilityCVE-2025-54865cvecve-2025-54865cwe-89
Published: Tue Aug 05 2025 (08/05/2025, 00:03:46 UTC)
Source: CVE Database V5
Vendor/Project: FTB-Gamepedia
Product: Tilesheets

Description

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.

Technical Details

Data Version
5.1
Assigner Short Name
GitHub_M
Date Reserved
2025-07-31T17:23:33.472Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 689154aead5a09ad00e467ff

Added to database: 8/5/2025, 12:47:42 AM

Last updated: 8/5/2025, 12:47:42 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats