Exposure of Private Personal Information to an Unauthorized Actor
CVE-2025-53625
Summary
The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several `#dpl` parameters can leak usernames that have been hidden using revision deletion, suppression, or the `hideuser` block flag. The issue affects universal-omega/dynamic-page-list3 versions prior to 3.6.4.
- LOW
- NETWORK
- NONE
- NONE
CWE-359 - Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
References
Advisory Timeline
- Published