CVE-2025-61647: UserInfoCard: Don't allow access to information about users who are suppressed if you don't have suppressor rights
Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Api/Rest/Handler/UserInfoHandler.Php.
This issue affects CheckUser: from a3dc1bbcc33acbcca6831d6afaccbb1054c93a57, 0584eb2ad564648aa3ce9c555dd044dda02b55f4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61647?
The severity of CVE-2025-61647 is classified as a moderate vulnerability due to its impact on user information accessibility.
How do I fix CVE-2025-61647?
To mitigate CVE-2025-61647, ensure that user suppressor rights are properly configured to prevent unauthorized access to suppressed user information.
What software is affected by CVE-2025-61647?
CVE-2025-61647 affects the Wikimedia Foundation CheckUser version between a3dc1bbcc33acbcca6831d6afaccbb1054c93a57 and 0584eb2ad564648aa3ce9c555dd044dda02b55f4.
What type of vulnerability is CVE-2025-61647?
CVE-2025-61647 is a user information disclosure vulnerability related to insufficient access control in the Wikimedia Foundation CheckUser.
Who can be affected by CVE-2025-61647?
Users without suppressor rights in the Wikimedia Foundation CheckUser are at risk of having their information accessed improperly due to CVE-2025-61647.