First published: Tue Apr 22 2025(Updated: )
ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically disabled even if the user did not hold the ManageWiki-restricted right. This issue has been patched in commit 00bebea. A workaround involves ensuring that any extensions requiring specific permissions in `$wgManageWikiExtensions` also require the same permissions for managing any conflicting extensions.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | <00bebea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32964 has been classified as a medium severity vulnerability due to the potential impact on user permissions.
To fix CVE-2025-32964, update the ManageWiki extension to the latest version after commit 00bebea.
If left unpatched, CVE-2025-32964 could lead to unauthorized users gaining the ability to disable restricted extensions.
CVE-2025-32964 affects all versions of ManageWiki prior to commit 00bebea.
Users of the ManageWiki extension within MediaWiki who have not updated to the latest version may be affected by CVE-2025-32964.