PT-2025-17560 · Mediawiki · Managewiki
Universal-Omega
·
Published
2025-04-22
·
Updated
2025-04-22
·
CVE-2025-32964
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ManageWiki (affected versions not specified)
Description
The issue concerns the ManageWiki MediaWiki extension, which allows users to manage wikis. Prior to a specific commit (00bebea), when a conflicting extension was enabled, a restricted extension would be automatically disabled, even if the user did not have the necessary ManageWiki-restricted right.
Recommendations
For versions prior to commit 00bebea, ensure that any extensions requiring specific permissions in
$wgManageWikiExtensions also require the same permissions for managing any conflicting extensions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability, but it has been patched in commit 00bebea.Exploit
Fix
LPE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Managewiki