CVE-2025-53498
Lack of Audit Logging in AbuseFilter
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
: Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks.This issue affects Mediawiki - AbuseFilter Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
:La vulnerabilidad de registro insuficiente en Wikimedia Foundation Mediawiki - AbuseFilter Extension permite ataques de fuga de datos. Este problema afecta a la extensión Mediawiki - AbuseFilter: desde 1.39.X hasta 1.39.13, desde 1.42.X hasta 1.42.7, desde 1.43.X hasta 1.43.2.
Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-06-30 CVE Reserved
- 2025-07-07 CVE Published
- 2025-07-08 CVE Updated
- 2025-08-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-778: Insufficient Logging
CAPEC
- CAPEC description not found.
References (2)
URL | Tag | Source |
---|---|---|
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1166844 | ||
https://phabricator.wikimedia.org/T397221 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wikimedia Foundation Search vendor "Wikimedia Foundation" | Mediawiki - AbuseFilter Extension Search vendor "Wikimedia Foundation" for product "Mediawiki - AbuseFilter Extension" | >= 1.43.0 < 1.43.2 Search vendor "Wikimedia Foundation" for product "Mediawiki - AbuseFilter Extension" and version " >= 1.43.0 < 1.43.2" | en |
Affected
|