Vulnerability Description
ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically disabled even if the user did not hold the ManageWiki-restricted right. This issue has been patched in commit 00bebea. A workaround involves ensuring that any extensions requiring specific permissions in `$wgManageWikiExtensions` also require the same permissions for managing any conflicting extensions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miraheze | Managewiki | < 2025-04-21 |
Related Weaknesses (CWE)
References
- https://github.com/miraheze/ManageWiki/commit/00bebea43a3e3ff0157b5f04df17c1d1e8Patch
- https://github.com/miraheze/ManageWiki/security/advisories/GHSA-ccrf-x5rp-gpprPatchVendor Advisory
FAQ
What is CVE-2025-32964?
CVE-2025-32964 is a vulnerability with a CVSS score of 4.6 (MEDIUM). ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically disabled even if the u...
How severe is CVE-2025-32964?
CVE-2025-32964 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32964?
Check the references section above for vendor advisories and patch information. Affected products include: Miraheze Managewiki.