CVE-2023-37252
Received Received - Intake

CheckUser Extension Username Exposure in MediaWiki

Vulnerability report for CVE-2023-37252, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mediawiki checkuser to 1.39.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2023-37252 is an information leak vulnerability in the MediaWiki CheckUser extension. It allows users without the suppress right to view hidden usernames in Special:CheckUserLog that should remain concealed. The issue occurs because the log displays usernames marked as hidden, such as those blocked with the 'Hide username from edits and lists' option.

Detection Guidance

To detect this vulnerability, check if the CheckUser extension is installed and if Special:CheckUserLog displays hidden usernames. Review MediaWiki logs for unauthorized access to hidden usernames in the CheckUser log entries.

Impact Analysis

This vulnerability could expose sensitive or private usernames to unauthorized users who have checkuser-log rights but lack the suppress right. It undermines user privacy and confidentiality, potentially revealing identities that were intended to be hidden.

Compliance Impact

This vulnerability could potentially impact compliance with data protection regulations like GDPR or HIPAA by exposing hidden usernames in logs. Unauthorized disclosure of personal data (usernames) may violate principles of data minimization and confidentiality required by these standards.

Mitigation Strategies

Apply the available patch for the CheckUser extension to prevent hidden usernames from being displayed in Special:CheckUserLog. Ensure only users with the suppress right can view hidden usernames. Update MediaWiki to a patched version (REL1_35, REL1_38, REL1_39, REL1_40, or master branch).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-37252. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart