Information Disclosure in MediaWiki AbuseFilter Extension by Wikimedia
CVE-2019-18987

5.3MEDIUM

Key Information:

Vendor

Mediawiki

Vendor
CVE Published:
15 November 2019

What is CVE-2019-18987?

A flaw in the AbuseFilter extension for MediaWiki allows for the potential disclosure of sensitive data through previous versions of an abuse filter, if it has been inadvertently made public. This vulnerability could lead to the exposure of private or sensitive information contained within the filter's definitions, raising significant privacy concerns for affected installations.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.