PT-2015-7706 · Mediawiki · Mediwiki Echo Extension

Legoktm

·

Published

2015-11-09

·

Updated

2015-11-10

·

CVE-2015-8007

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediWiki Echo extension (affected versions not specified)
Description The issue concerns the Echo extension for MediWiki, which fails to properly implement the hideuser functionality. This allows remote authenticated users to view hidden usernames in certain notifications, such as Thanks notifications, that are not based on revisions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8007

Affected Products

Mediwiki Echo Extension