CVE-2025-32698: LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/LogPager.Php.
This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32698?
CVE-2025-32698 is a moderate severity vulnerability that exposes sensitive information to unauthorized actors in certain versions of MediaWiki.
How do I fix CVE-2025-32698?
To mitigate CVE-2025-32698, upgrade your MediaWiki installation to versions 1.39.12, 1.42.6, or 1.43.1 or later.
What specific component is affected by CVE-2025-32698?
CVE-2025-32698 specifically affects the includes/logging/LogPager.php component in MediaWiki.
Which versions of MediaWiki are vulnerable to CVE-2025-32698?
Versions of MediaWiki prior to 1.39.12, 1.42.6, and 1.43.1 are vulnerable to CVE-2025-32698.
Who is the vendor for CVE-2025-32698?
The vendor for CVE-2025-32698 is the Wikimedia Foundation, which maintains MediaWiki.