The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.Referenceshttps://phabricator.wikimedia.org/T306463https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SemanticDrilldown/+/785213