Sensitive Information Exposure in CheckUser Extension for MediaWiki
CVE-2019-18611

6.5MEDIUM

Key Information:

Vendor

Mediawiki

Status
Vendor
CVE Published:
29 October 2019

What is CVE-2019-18611?

A flaw was detected in the CheckUser extension for MediaWiki, allowing certain users to access oversighted edit summaries through the MediaWiki API. This exposure poses a risk as it could unveil sensitive information that should remain confidential based on user access privileges. Users who should not have visibility over such edit summaries are able to retrieve them, emphasizing the importance of securing APIs and validating user permissions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.