PT-2025-17560 · Mediawiki · Managewiki

Universal-Omega

·

Published

2025-04-22

·

Updated

2025-04-22

·

CVE-2025-32964

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions ManageWiki (affected versions not specified)
Description The issue concerns the ManageWiki MediaWiki extension, which allows users to manage wikis. Prior to a specific commit (00bebea), when a conflicting extension was enabled, a restricted extension would be automatically disabled, even if the user did not have the necessary ManageWiki-restricted right.
Recommendations For versions prior to commit 00bebea, ensure that any extensions requiring specific permissions in $wgManageWikiExtensions also require the same permissions for managing any conflicting extensions. At the moment, there is no information about a newer version that contains a fix for this vulnerability, but it has been patched in commit 00bebea.

Exploit

Fix

LPE

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-32964
GHSA-CCRF-X5RP-GPPR

Affected Products

Managewiki