Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dianliang233

#24603of 56,335
10Total CVSS
Vulnerabilities · 1
PT-2025-42865
10
2025-10-21
Unknown · Lockdown Extension · CVE-2025-12004
**Name of the Vulnerable Software and Affected Versions** Mediawiki - Lockdown Extension versions prior to 1.42 **Description** The Mediawiki Lockdown Extension contains a flaw related to incorrect permission assignment for critical resources, which allows for privilege abuse. The issue resides in the compare API module and enables attackers to bypass permissions, potentially leading to complete privilege escalation without authentication. The problem is fixed in the Mediawiki Core Action API. **Recommendations** Upgrade to version 1.42 or later to resolve this vulnerability.