PT-2015-7706 · Mediawiki · Mediwiki Echo Extension

Legoktm

·

Publicado

2015-11-09

·

Atualizado

2015-11-10

·

CVE-2015-8007

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediWiki Echo extension (affected versions not specified)
Description The issue concerns the Echo extension for MediWiki, which fails to properly implement the hideuser functionality. This allows remote authenticated users to view hidden usernames in certain notifications, such as Thanks notifications, that are not based on revisions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8007

Produtos afetados

Mediwiki Echo Extension