PT-2025-16010 · Mediawiki+2 · Mediawiki+2

David Levy

+1

·

Published

2025-04-10

·

Updated

2025-11-05

·

CVE-2025-32697

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: MediaWiki versions prior to 1.42.6, 1.43.1
Description: The issue is related to an Improper Preservation of Permissions vulnerability. It affects program files such as includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, and includes/Permissions/RestrictionStore.Php.
Recommendations: For versions prior to 1.42.6, update to version 1.42.6 or later. For version 1.43.0, update to version 1.43.1 or later. As a temporary workaround, consider restricting access to the affected program files until a patch is available.

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06079
BIT-MEDIAWIKI-2025-32697
CVE-2025-32697
DSA-5901-1
MGASA-2025-0260

Affected Products

Debian
Mediawiki
Red Os