216.73.217.22

CVE-2025-12004

· Published 21/10/2025 07:15 · Modified 21/10/2025 19:31

Labels: CVE-2025-12004 2025-10-21CVE-2025-12004CWE-732c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

Essential information

Published
21/10/2025 07:15
Modified
21/10/2025 19:31
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: from master before 1.42.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
NVD
View on NVD

Affected products (CPE)

ProductCPE
wikimedia / mediawiki cpe:2.3:a:wikimedia:mediawiki:-:<1.42:*:*:*:*:*:*
wikimedia / mediawiki lockdown extension cpe:2.3:a:wikimedia:mediawiki_lockdown_extension:*:*:*:*:*:*:*

References