CVE-2025-61649: UserInfoCard: Check that performing user has permission to view log entries for number of past blocks
Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Services/CheckUserUserInfoCardService.Php.
This issue affects CheckUser: from 7cedd58781d261f110651b6af4f41d2d11ae7309.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61649?
CVE-2025-61649 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive log entries.
How do I fix CVE-2025-61649?
To fix CVE-2025-61649, ensure that the permission checks for viewing past log entries are correctly implemented in the CheckUser service.
Who is affected by CVE-2025-61649?
CVE-2025-61649 affects users of the Wikimedia Foundation's CheckUser service who may not have proper permissions to access log entries.
What is the impact of CVE-2025-61649?
The impact of CVE-2025-61649 includes potential exposure of sensitive information through unauthorized access to log entries.
Is there a patch available for CVE-2025-61649?
As of now, it is recommended to monitor the project's repository for updates on patches related to CVE-2025-61649.