Vulnerability Description
Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: from master before 1.42.
Related Weaknesses (CWE)
References
- https://gerrit.wikimedia.org/r/q/Id275382743957004fa7fc56318fc104d8e2d267b
- https://phabricator.wikimedia.org/T397521
- https://phabricator.wikimedia.org/T397521
FAQ
What is CVE-2025-12004?
CVE-2025-12004 is a documented vulnerability. Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affe...
How severe is CVE-2025-12004?
CVSS scoring is not yet available for CVE-2025-12004. Check NVD for updates.
Is there a patch for CVE-2025-12004?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.