PT-2020-9834 · Mediawiki · Mediawiki Abusefilter Extension

Published

2020-03-20

·

Updated

2021-07-21

·

CVE-2019-16528

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki AbuseFilter extension versions REL1 32 through REL1 33
Description An issue in the AbuseFilter extension for MediaWiki allows attackers to obtain sensitive information, such as deleted or suppressed usernames and summaries, from AbuseLog revision data through the includes/special/SpecialAbuseLog.php file.
Recommendations For versions REL1 32 and REL1 33, consider restricting access to the SpecialAbuseLog.php file until a patch is available. As a temporary workaround, avoid using the affected AbuseLog revision data in the includes/special/SpecialAbuseLog.php file until the issue is resolved.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16528

Affected Products

Mediawiki Abusefilter Extension