Information disclosure in MediaWiki - CVE-2025-6593
Published: August 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application does not verify the email address when sending the "{{SITENAME}} registered email address has been changed" email message, revealing the IP address of the user. A remote attacker can gain access to sensitive information.
Affected software
Debian Linux
mediawiki (Debian package)
How to mitigate CVE-2025-6593
mediawiki (Debian package) - update to 1:1.39.13-1~deb12u1