Vulnerability in Wikimedia Foundation's CheckUser Tool
CVE-2025-61647
0.3LOW
What is CVE-2025-61647?
A vulnerability exists within the Wikimedia Foundation's CheckUser tool, specifically in the src/Api/Rest/Handler/UserInfoHandler.php file. This flaw could potentially allow unauthorized users to access sensitive information, undermining the tool's integrity by bypassing expected authorization mechanisms. The affected versions include specific commits, which if not addressed, may compromise user data security.
Affected Version(s)
CheckUser a3dc1bbcc33acbcca6831d6afaccbb1054c93a57, 0584eb2ad564648aa3ce9c555dd044dda02b55f4
