Vulnerability Description
Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ftb-Gamepedia | Tilesheets | >= 5.0.1, < 5.0.3 |
Related Weaknesses (CWE)
References
- https://github.com/FTB-Gamepedia/Tilesheets/blob/8debbf8ee6ddb02bf9c756bab5c085bProduct
- https://github.com/FTB-Gamepedia/Tilesheets/security/advisories/GHSA-hqfr-7cm9-4ExploitVendor Advisory
- https://github.com/FTB-Gamepedia/Tilesheets/security/advisories/GHSA-hqfr-7cm9-4ExploitVendor Advisory
FAQ
What is CVE-2025-54865?
CVE-2025-54865 is a vulnerability with a CVSS score of 7.3 (HIGH). Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to inser...
How severe is CVE-2025-54865?
CVE-2025-54865 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54865?
Check the references section above for vendor advisories and patch information. Affected products include: Ftb-Gamepedia Tilesheets.