CVE-2025-62699
BaseFortify
Publication date: 2025-10-21
Last updated on: 2025-10-21
Assigner: wikimedia-foundation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wikimedia | mediawiki | 1.39 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Exposure of Sensitive Information to an Unauthorized Actor in the Wikimedia Foundation Mediawiki - CheckUser Extension. It allows an attacker to perform Footprinting, which means gathering information about the system or users without authorization. The issue affects versions from master before 1.39 of the CheckUser Extension.
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized disclosure of sensitive information, potentially allowing attackers to gather data about users or the system. This could compromise privacy and security by exposing information that should be protected.