Junglewise Threat Intelligence

CVE-2023-37253: MediaWiki ProofreadPage information disclosure in API

CVE-2023-37253 · Severity: low · CVSS 3.1 · Published 2026-09-14

Executive brief

The ProofreadPage extension for MediaWiki leaks the names of suppressed users—accounts that administrators have hidden from public view—through the extension's API responses and configuration variables. An unauthenticated attacker can discover hidden usernames that should not be visible, potentially compromising privacy protections designed to safeguard sensitive editor accounts.

Technical details

The vulnerability is an information disclosure (CWE-200) in the ProofreadPage extension where suppressed usernames are returned in API responses and exposed via client-side JavaScript config variables. The root cause is missing user suppression checks when constructing Page quality metadata and revision data; the extension does not verify the isHidden() status of users before returning their names through public-facing interfaces. An unauthenticated attacker on the network can retrieve suppressed usernames by querying the MediaWiki API for page revisions or accessing the mw.config object in the browser console without authentication. The patch (confirmed in Gerrit) adds isHidden() checks before exposing reviewer names, preventing suppressed usernames from appearing in API output and config variables.

Affected products

  • MediaWiki ProofreadPage through 1.39.3

Timeline

  • 2023-01-13: disclosed
  • 2023-01: patched: Patches committed to master, REL1_38, REL1_39, and REL1_40 branches

References