CVE-2025-62661: Do permission checking when getting counts of global and local edits, new articles and thanks
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension: from 1.43 before 1.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62661?
CVE-2025-62661 is considered a medium severity vulnerability due to incorrect default permissions that could lead to unauthorized access.
How do I fix CVE-2025-62661?
To fix CVE-2025-62661, update the affected Mediawiki extensions to versions greater than 1.44.
Which versions are affected by CVE-2025-62661?
CVE-2025-62661 affects versions 1.43 and below of the Mediawiki - Thanks Extension and Mediawiki - Growth Experiments Extension.
What types of vulnerabilities are related to CVE-2025-62661?
CVE-2025-62661 is related to access control vulnerabilities that allow functionality to be accessed without proper constraints.
Who is impacted by CVE-2025-62661?
Users and administrators of the affected Wikimedia Foundation Mediawiki extensions are impacted by CVE-2025-62661.