PT-2025-29121 · Mediawiki · Dynamicpagelist3

Markus-Rost

·

Published

2025-07-10

·

Updated

2025-07-11

·

CVE-2025-53625

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: DynamicPageList3 extension versions prior to 3.6.4
Description: The DynamicPageList3 extension for MediaWiki contains an issue where certain parameters can reveal usernames that have been hidden through revision deletion, suppression, or the hideuser block flag. Specifically, the parameters adduser, addauthor, addlasteditor, and addcontribution output usernames using placeholders like %USER% and %CONTRIBUTOR%, even when those usernames have been hidden. Additionally, parameters like lastrevisionbefore, allrevisionsbefore, firstrevisionsince, and allrevisionssince can expose suppressed usernames when used with user-related output placeholders. Parameters such as createdby, notcreatedby, modifiedby, notmodifiedby, lastmodifiedby, and notlastmodifiedby can indirectly reveal hidden usernames when used in queries.
Recommendations: DynamicPageList3 extension versions prior to 3.6.4 should be updated to version 3.6.4 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-53625
GHSA-7PGW-Q3QP-6PGQ

Affected Products

Dynamicpagelist3