PT-2020-9834 · Mediawiki · Mediawiki Abusefilter Extension
Published
2020-03-20
·
Updated
2021-07-21
·
CVE-2019-16528
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki AbuseFilter extension versions REL1 32 through REL1 33
Description
An issue in the AbuseFilter extension for MediaWiki allows attackers to obtain sensitive information, such as deleted or suppressed usernames and summaries, from AbuseLog revision data through the includes/special/SpecialAbuseLog.php file.
Recommendations
For versions REL1 32 and REL1 33, consider restricting access to the SpecialAbuseLog.php file until a patch is available.
As a temporary workaround, avoid using the affected AbuseLog revision data in the includes/special/SpecialAbuseLog.php file until the issue is resolved.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mediawiki Abusefilter Extension