Sensitive Information Exposure in Wikimedia Foundation's MediaWiki CheckUser Extension
CVE-2025-62699

6.9MEDIUM

What is CVE-2025-62699?

The MediaWiki CheckUser Extension developed by the Wikimedia Foundation exposes sensitive information that can be accessed by unauthorized actors. This vulnerability allows attackers to potentially footprint users, compromising their privacy and security. Versions before 1.39 of the extension are affected, necessitating prompt updates to mitigate potential risks.

Affected Version(s)

Mediawiki - CheckUser Extension master < 1.39

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dreamy_Jazz
abi_
.
CVE-2025-62699 : Sensitive Information Exposure in Wikimedia Foundation's MediaWiki CheckUser Extension