Description
An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.
Published: 2026-09-14
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

An issue was identified in the ProofreadPage extension for MediaWiki versions through 1.39.3 that permits the revelation of data about suppressed users via the extension’s API and certain configuration variables. The flaw is a classic information‑disclosure weakness (CWE‑669). If an attacker can query the API or read the relevant configuration data, they may discover the identities or status of users that administrators intended to hide, potentially exposing sensitive user relationships or activity logs.

Affected Systems

The vulnerability impacts the MediaWiki ProofreadPage extension up to and including version 1.39.3. Any installation of this extension released at that point or earlier is susceptible. No other MediaWiki components are listed as affected.

Risk and Exploitability

The CVSS base score of 3.1 signals a low severity. An EPSS score of less than 1% reflects a very low likelihood of exploitation, and the issue is absent from the CISA KEV catalog. The presumed attack vectors are through the public API, which a remote attacker could use, or by accessing configuration files, which would require local read permissions. Given the low score, the immediate threat is modest, but exposed suppressed user data can still aid targeted social engineering or compliance investigations.

Generated by OpenCVE AI on September 15, 2026 at 16:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the ProofreadPage extension to a newer release that contains the fix once it becomes available.
  • Restrict access to the extension’s API endpoints so that only authorized users may request suppressed‑user data, or adjust MediaWiki ACLs to block such queries from unauthenticated users.
  • Configure the ProofreadPage extension or MediaWiki to prevent the exposure of suppressed user identifiers in configuration variables, or disable the relevant API module until the vulnerability is resolved.

Generated by OpenCVE AI on September 15, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediawiki
Mediawiki proofreadpage
Vendors & Products Mediawiki
Mediawiki proofreadpage

Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Suppressed User Data Leakage via ProofreadPage API and Config Variables

Mon, 14 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Suppressed User Data Leakage via ProofreadPage API and Config Variables

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.
Weaknesses CWE-669
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Mediawiki Proofreadpage
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:06:44.673Z

Reserved: 2023-06-29T00:00:00.000Z

Link: CVE-2023-37253

cve-icon Vulnrichment

Updated: 2026-09-14T15:06:38.841Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T06:16:53.740

Modified: 2026-09-16T19:31:54.210

Link: CVE-2023-37253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:58Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres