Impact
An issue exists in the CheckUser extension for MediaWiki that causes the Special:CheckUserLog page to display usernames that should remain hidden. The flaw results in accidental leakage of user identities, compromising the privacy of users tracked through CheckUser. The weakness is identified as CWE-669, Improper Restriction of Operations within a Component, indicating a failure to enforce intended access controls on log data. The disclosure of hidden usernames may allow an attacker to link otherwise anonymized user activity, undermining user anonymity and potentially facilitating social engineering or targeted attacks.
Affected Systems
The vulnerability affects installations of the CheckUser extension for MediaWiki through version 1.39.3. Any MediaWiki instance using a CheckUser extension up to and including 1.39.3, regardless of other MediaWiki components, is susceptible. The specific vendor and product is MediaWiki’s CheckUser extension, and the affected releases are any builds that incorporate the extension prior to its remediation in later releases.
Risk and Exploitability
Because the exploit requires access to the Special:CheckUserLog page, the attack surface is limited to users who have the rights to view that page; this inference is made as the advisory does not explicitly state the required permissions, but it is likely that only administrators or users with the MediaWiki privileged ‘checkuser’ right can access it. The CVSS base score of 3.1 indicates a low severity; however, the risk is amplified in environments where user anonymity is a requirement. The EPSS score is < 1%, indicating a very low exploitation probability at the time of the advisory, meaning a competent attacker could simply request the page. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation at the time of reporting. The likely attack vector is through an authenticated privileged user accessing the Special:CheckUserLog page; this is inferred from the context rather than explicitly stated.
OpenCVE Enrichment