Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fr28-p2jh-93mm

Опубликовано: 15 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

EPSS

Процентиль: 40%
0.00184
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 3 года назад

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

CVSS3: 4.3
nvd
почти 3 года назад

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

CVSS3: 4.3
debian
почти 3 года назад

An issue was discovered in the VisualEditor extension in MediaWiki bef ...

EPSS

Процентиль: 40%
0.00184
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668