CVE-2025-12004
CVE-2025-12004
10.0
CriticalPublished:
Last updated:
Source:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Deferred
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: from master before 1.42.
References
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
https://gerrit.wikimedia.org/r/q/Id275382743957004fa7fc56318fc104d8e2d267bc4f26cc8-17ff-4c99-b5e2-38fc1793eacc
https://phabricator.wikimedia.org/T397521134c704f-9b21-4f2e-91b3-4a467353bcc0
https://phabricator.wikimedia.org/T397521