Wikimedia Foundation MediaWiki SocialProfile Extension Information Exposure Vulnerability
Vulnerability
A vulnerability in the Wikimedia Foundation MediaWiki SocialProfile Extension allows unauthorized users to access sensitive information. This issue arises because the Special:EditProfile page does not properly respect the visibility settings of profile fields. As a result, a user with the 'editothersprofiles' permission can view 'hidden' fields or those designated for 'friends' or 'friends of friends' when they are not in the user's friend circle. The vulnerability affects MediaWiki SocialProfile Extension versions 1.39.X prior to 1.39.11, 1.41.X prior to 1.41.3, and 1.42.X prior to 1.42.2.
Impact
Exploitation of this vulnerability leads to unauthorized access to sensitive profile information, including fields marked as 'hidden' or restricted to 'friends' or 'friends of friends'.
Reproduction
To reproduce this vulnerability, first create two accounts: 'Admin' and 'User'. Ensure that 'Admin' has the 'editothersprofiles' permission. As 'User', navigate to Special:UpdateProfile' and set one or more fields to 'hidden' or limited visibility, such as 'friends' or 'friends of friends'. After saving the profile, log out and log back in as 'Admin'. Then, access 'Special:EditProfile/User'. 'Admin' will be able to view the 'hidden' field values, despite not being authorized to see them.
Remediation
Users can update to MediaWiki SocialProfile Extension versions 1.39.11, 1.41.3, or 1.42.2, where this vulnerability has been patched.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
