CVE-2023-37253 Overview
CVE-2023-37253 is an information disclosure vulnerability in the ProofreadPage extension for MediaWiki through version 1.39.3. The extension leaks information about suppressed users through the MediaWiki API and configuration variables. Suppressed users are accounts hidden from public view by administrators, typically for privacy or moderation reasons. This flaw undermines that suppression by exposing identifying data through unintended channels. The vulnerability is classified under [CWE-669] Incorrect Resource Transfer Between Spheres.
Critical Impact
Authenticated attackers with low privileges can retrieve information about suppressed MediaWiki users via the ProofreadPage API, breaking the confidentiality guarantees of user suppression.
Affected Products
- MediaWiki ProofreadPage extension through version 1.39.3
- MediaWiki installations with ProofreadPage enabled
- Wikimedia projects using ProofreadPage (for example, Wikisource)
Discovery Timeline
- 2026-09-14 - CVE-2023-37253 published to NVD
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2023-37253
Vulnerability Analysis
The ProofreadPage extension exposes user metadata through API responses and configuration variables without applying MediaWiki's suppression controls. When a user is suppressed, their username and related identifiers should be hidden from unprivileged consumers. ProofreadPage does not honor this restriction consistently. The result is a cross-boundary information transfer where restricted user data reaches contexts that should not receive it. Because ProofreadPage powers page proofreading workflows on projects such as Wikisource, the exposure applies to any wiki running the extension.
Root Cause
The root cause is improper enforcement of user suppression state within ProofreadPage's data serialization paths. API endpoints and JavaScript configuration variables that expose page contributor information do not filter out suppressed accounts. This aligns with [CWE-669], where a resource is transferred from a restricted sphere to a less restricted one without appropriate access checks.
Attack Vector
An attacker with a low-privileged authenticated account queries the MediaWiki API endpoints exposed by ProofreadPage or reads embedded configuration variables from rendered pages. The response includes information about users whose identities administrators previously suppressed. No user interaction beyond the attacker's own requests is required. Successful exploitation reveals suppressed usernames or associated identifiers, which may include accounts hidden for safety, legal, or policy reasons. See the Wikimedia Task T326952 tracking entry for maintainer discussion and remediation details.
Detection Methods for CVE-2023-37253
Indicators of Compromise
- API request logs showing repeated queries to ProofreadPage endpoints returning contributor metadata
- Access patterns targeting pages associated with suppressed revisions or users
- Anomalous scraping activity from low-privileged accounts against Index or Page namespaces
Detection Strategies
- Compare user identifiers returned in ProofreadPage API responses against the local suppression list
- Instrument ProofreadPage API handlers to log when suppressed user records are serialized
- Review MediaWiki abuse filter logs for high-volume metadata retrieval by non-administrator accounts
Monitoring Recommendations
- Enable request logging on API modules registered by ProofreadPage and forward logs to a central SIEM
- Alert on authenticated sessions retrieving contributor lists at rates inconsistent with normal editorial workflows
- Correlate ProofreadPage API access with recent administrative suppression actions to identify targeted reconnaissance
How to Mitigate CVE-2023-37253
Immediate Actions Required
- Upgrade the ProofreadPage extension to a version later than 1.39.3 that includes the fix referenced in Wikimedia Task T326952
- Audit recent API access logs for queries that may have retrieved suppressed user information
- Restrict ProofreadPage API endpoints to authenticated users where feasible pending the upgrade
Patch Information
Refer to the Wikimedia Phabricator task T326952 for the upstream fix and associated patch commits. Administrators should apply the vendor-supplied update matching their MediaWiki release channel and redeploy the extension.
Workarounds
- Disable the ProofreadPage extension on wikis where the proofreading workflow is not actively used
- Restrict access to Index and Page namespaces via user group permissions to limit metadata exposure
- Remove or filter ProofreadPage-specific JavaScript configuration variables from rendered output using site-level customizations
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
