Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: from master before 1.42.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 21 Oct 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: from master before 1.42. | |
Title | The compare API module breaks Extension:Lockdown | |
Weaknesses | CWE-732 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2025-10-21T14:08:28.782Z
Reserved: 2025-10-21T06:09:56.596Z
Link: CVE-2025-12004

Updated: 2025-10-21T13:41:48.932Z

Status : Received
Published: 2025-10-21T07:15:36.643
Modified: 2025-10-21T14:15:47.260
Link: CVE-2025-12004

No data.

No data.