PT-2025-42865 · Unknown+1 · Lockdown Extension+2

Daniel

+1

·

Published

2025-10-21

·

Updated

2025-10-21

·

CVE-2025-12004

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Mediawiki - Lockdown Extension versions prior to 1.42
Description The Mediawiki Lockdown Extension contains a flaw related to incorrect permission assignment for critical resources, which allows for privilege abuse. The issue resides in the compare API module and enables attackers to bypass permissions, potentially leading to complete privilege escalation without authentication. The problem is fixed in the Mediawiki Core Action API.
Recommendations Upgrade to version 1.42 or later to resolve this vulnerability.

Exploit

Fix

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12004

Affected Products

Lockdown Extension
Mediawiki
Mediawiki Core Action Api