Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-30153

Опубликовано: 15 апр. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
Версия до 1.31.13 (исключая)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
Версия от 1.32.0 (включая) до 1.35.2 (исключая)

EPSS

Процентиль: 40%
0.00184
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668
CWE-668

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 3 года назад

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

CVSS3: 4.3
debian
почти 3 года назад

An issue was discovered in the VisualEditor extension in MediaWiki bef ...

CVSS3: 4.3
github
почти 3 года назад

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

EPSS

Процентиль: 40%
0.00184
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668
CWE-668