Skip to main content

Exposure of Private Personal Information to an Unauthorized Actor

CVE-2025-53625

Severity High
Score 8.7/10

Summary

The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several `#dpl` parameters can leak usernames that have been hidden using revision deletion, suppression, or the `hideuser` block flag. The issue affects universal-omega/dynamic-page-list3 versions prior to 3.6.4.

  • LOW
  • NETWORK
  • NONE
  • NONE

CWE-359 - Exposure of Private Personal Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Advisory Timeline

  • Published