CVE-2025-53625 Information

Description

The DynamicPageList3 extension is a reporting tool for MediaWiki listing category members and intersections with various formats and details. Several dpl parameters can leak usernames that have been hidden using revision deletion suppression or the hideuser block flag. The vulnerability is fixed in 3.6.4.

Reference

https://github.com/Universal-Omega/DynamicPageList3/commit/a3dae0c89fb4214390c29ceffa23bbe2099986d6 https://github.com/Universal-Omega/DynamicPageList3/security/advisories/GHSA-7pgw-q3qp-6pgq https://github.com/Universal-Omega/DynamicPageList3/security/advisories/GHSA-7pgw-q3qp-6pgq

CNNVD-202507-1528 (Published: 2025-07-10)

Share on: