CVE-2025-32964

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 285

Summary

CVE-2025-32964 affects the ManageWiki MediaWiki extension, which allows users to manage wikis. Before commit 00bebea, enabling a conflicting extension would result in the automatic disabling of a restricted extension, even if the user did not hold the necessary ManageWiki permissions. This vulnerability has been addressed in commit 00bebea. To mitigate this risk, it is recommended to ensure that any extensions requiring specific permissions in `$wgManageWikiExtensions` also require the same permissions for managing conflicting extensions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share