CVE 0.3 LOW

UserInfoCard: Don’t allow access to information about users who are suppressed if you don’t have suppressor rights_CVE-2025-61647

0.3 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U

Description

Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Api/Rest/Handler/UserInfoHandler.Php.

This issue affects CheckUser: from a3dc1bbcc33acbcca6831d6afaccbb1054c93a57, 0584eb2ad564648aa3ce9c555dd044dda02b55f4.

Basic Information

ID CVE-2025-61647
Source wikimedia-foundation
Published Feb 3, 2026 at 00:02

Affected Product

Vendor Wikimedia Foundation
Product CheckUser
Version a3dc1bbcc33acbcca6831d6afaccbb1054c93a57, 0584eb2ad564648aa3ce9c555dd044dda02b55f4
Affected Versions Wikimedia Foundation CheckUser a3dc1bbcc33acbcca6831d6afaccbb1054c93a57, 0584eb2ad564648aa3ce9c555dd044dda02b55f4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.