CVE-2025-32700
AbuseFilter log interfaces expose global private and hidden filters when central DB is not available
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseLog.Php, includes/Pager/AbuseLogPager.Php, includes/Special/SpecialAbuseLog.Php, includes/View/AbuseFilterViewExamine.Php.
This issue affects AbuseFilter: from >= 1.43.0 before 1.43.1.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/RE:M/U:Green
Produtos afetados
Wikimedia Foundation · MediaWikiQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://phabricator.wikimedia.org/T389235