CVE-2025-53501: Content Access Bypass in Scribunto
Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53501?
CVE-2025-53501 has been rated as a critical severity vulnerability due to its impact on access control.
What versions of the Wikimedia Foundation Mediawiki - Scribunto Extension are affected by CVE-2025-53501?
CVE-2025-53501 affects versions prior to 1.39.12, 1.42.7, and 1.43.2 of the Mediawiki - Scribunto Extension.
How do I fix CVE-2025-53501?
Fix CVE-2025-53501 by upgrading the Mediawiki - Scribunto Extension to version 1.39.12 or later, 1.42.7 or later, or 1.43.2 or later.
What type of vulnerability is CVE-2025-53501?
CVE-2025-53501 is categorized as an improper access control vulnerability.
What functionalities does CVE-2025-53501 affect?
CVE-2025-53501 allows accessing functionalities that are not properly constrained by authorization within the Mediawiki - Scribunto Extension.