Mediawiki · Mediawiki Casauth Extension · CVE-2020-35623
**Name of the Vulnerable Software and Affected Versions**
MediaWiki CasAuth extension versions through 1.35.1
**Description**
An issue was discovered due to improper username validation, allowing user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat user" who has a similar username, as demonstrated by usernames that differ only in bidirectional override symbols or blank space.
**Recommendations**
For MediaWiki CasAuth extension versions through 1.35.1, update to a version that fixes the improper username validation issue to prevent user impersonation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.