CVE-2025-32964

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
22/04/2025
Last modified:
19/09/2025

Description

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically disabled even if the user did not hold the ManageWiki-restricted right. This issue has been patched in commit 00bebea. A workaround involves ensuring that any extensions requiring specific permissions in `$wgManageWikiExtensions` also require the same permissions for managing any conflicting extensions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:miraheze:managewiki:*:*:*:*:*:mediawiki:*:* 2025-04-21 (excluding)