CVE-2025-62661
BaseFortify
Publication date: 2025-10-21
Last updated on: 2025-10-22
Assigner: wikimedia-foundation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wikimedia | mediawiki_thanks_extension | * |
| wikimedia | mediawiki | 1.44 |
| wikimedia | mediawiki_growth_experiments_extension | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Incorrect Default Permissions issue in the Wikimedia Foundation's Mediawiki Thanks Extension and Growth Experiments Extension. It allows access to functionality that is not properly restricted by Access Control Lists (ACLs), meaning users might be able to use features they should not have permission to access.
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized access to certain functions within the affected Mediawiki extensions, potentially allowing users to perform actions beyond their intended permissions. This could result in misuse or abuse of the system's features.