In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
References
Configurations
Information
Published : 2019-09-26 02:15
Updated : 2021-07-21 11:39
NVD link : CVE-2019-16738
Mitre link : CVE-2019-16738
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
