---
id: CVE-2023-37253
title: >-
  An issue was discovered in the ProofreadPage extension for MediaWiki through
  1.39.3
summary: >-
  An issue was discovered in the ProofreadPage extension for MediaWiki through
  1.39.3. It leaks information about a suppressed user via the API and config
  variables.
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-669
vendor: MediaWiki
product: ProofreadPage
affected:
  - ProofreadPage < 1.35.11
  - ProofreadPage >= 1.36.0 < 1.38.7
  - ProofreadPage >= 1.39.0 < 1.39.4
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:31:54.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-37253'
references:
  - url: 'https://phabricator.wikimedia.org/T326952'
    label: cve@mitre.org
  - url: 'https://phabricator.wikimedia.org/T326952'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00197
epssPercentile: 0.09713
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T15:06:09.611404Z'
ingestedAt: '2026-09-14T15:23:07.426Z'
---

## Overview

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
