8.8

CVE-2025-53501

Exploit

Content Access Bypass in Scribunto

Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XtexScribunto Version- SwPlatformmediawiki
   MediawikiMediawiki Version >= 1.39.0 < 1.39.12
   MediawikiMediawiki Version >= 1.42.0 < 1.42.7
   MediawikiMediawiki Version >= 1.43.0 < 1.43.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.223
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://phabricator.wikimedia.org/T397524
Patch
Exploit
Issue Tracking
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Scribunto/+/1164541
Patch