
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61652 is an improper input validation vulnerability in the Wikimedia Foundation's DiscussionTools MediaWiki extension. The flaw causes the Action API endpoint discussiontoolspageinfo to fail to check for authorizeRead permissions on a page, potentially exposing restricted page information to unauthorized users. It affects DiscussionTools versions prior to 1.43.4 and 1.44.1. The vulnerability was published on February 3, 2026, and carries a CVSS v4.0 base score of 2.7 (Low) (Red Hat CVE, ENISA EUVD).
The root cause is classified as CWE-20 (Improper Input Validation), specifically a missing authorization check in the DiscussionTools Action API. The discussiontoolspageinfo API endpoint does not invoke the authorizeRead permission check before returning page metadata, allowing any network-accessible user — including unauthenticated ones — to query information about pages that may be access-restricted. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity. The vulnerability is tracked in the Wikimedia Phabricator issue tracker at T397580 (ENISA EUVD, Infinitsec).
Exploitation of this vulnerability results in a limited confidentiality impact: an unauthenticated or low-privileged attacker can retrieve metadata or information about MediaWiki pages that are intended to be restricted from public view. There is no integrity or availability impact, and the vulnerability does not enable code execution, privilege escalation, or lateral movement. The scope is limited to the DiscussionTools extension's API endpoint on affected MediaWiki installations (Red Hat CVE, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-61652. The EPSS score is approximately 0.052% (0.000520), indicating a very low probability of exploitation in the near term. The exploit maturity is rated as "Unreported" in the CVSS v4.0 assessment, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE, Feedly).
https://[target]/api.php?action=discussiontoolspageinfo&page=[restricted_page_title]&format=json.authorizeRead permission check, disclosing metadata about the restricted page to the unauthenticated requester./api.php with action=discussiontoolspageinfo targeting page titles that are access-restricted, originating from unexpected IP addresses.discussiontoolspageinfo from unauthenticated sessions or accounts without read permissions for the queried pages.discussiontoolspageinfo endpoint in a short time window, potentially indicating automated enumeration of restricted page names.Wikimedia Foundation has released patched versions of DiscussionTools: 1.43.4 and 1.44.1. MediaWiki administrators should upgrade the DiscussionTools extension to one of these versions immediately. As a temporary workaround, administrators may consider disabling the DiscussionTools extension until the patch can be applied, particularly on wikis with sensitive restricted content. Debian has also issued a security advisory (DSA-6085-1) for MediaWiki packages that includes this fix (Debian Security, ENISA EUVD).
The vulnerability received limited industry attention given its low CVSS score and narrow impact. Debian issued a security advisory (DSA-6085-1) covering this and related MediaWiki vulnerabilities, and Tenable published detection plugins for it. A blog post by a Wikimedia developer discussed the broader context of XSS protections in MediaWiki, tangentially referencing this class of issues (Debian Security, Tenable Plugin, Bawolff Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."