Impact
The PageTriage extension contains a data query flaw that permits the retrieval of suppressed reviewer usernames. This exposes confidential editorial metadata and personal identifiers, violating reviewer privacy and the integrity of the moderation process. The vulnerability is a direct information elicitation weakness that can reveal sensitive data to an internal or external adversary. Repeated exploitation could erode trust in the system’s confidentiality guarantees. The fixed CWE for the defect is CWE-202.
Affected Systems
MediaWiki PageTriage extension versions 1.46, 1.45, and 1.43 are affected. The flaw is present on MediaWiki instances that enable PageTriage for content moderation. Any site deploying these specific extension releases without remediation is susceptible to the disclosure.
Risk and Exploitability
The CVSS score of 1.2 reflects a low severity impact, and the EPSS score is not available, implying a limited known exploitation trend. The flaw does not require special credentials; the attack vector is inferred to be possible through unauthenticated or minimally privileged access to PageTriage listings. While the risk of immediate compromise is modest, accidental or intentional disclosure undermines the privacy of reviewers and may impair the reputation of the site.
OpenCVE Enrichment