PT-2020-9835 · Mediawiki · Mediawiki+1

Published

2020-03-19

·

Updated

2020-03-24

·

CVE-2019-16529

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki CheckUser extension versions through 1.35.0
Description An issue was discovered in the CheckUser extension for MediaWiki, where oversighted edit summaries are still visible in CheckUser results, violating MediaWiki's permissions model.
Recommendations For versions through 1.35.0, consider restricting access to CheckUser results to minimize the risk of exploitation until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-16529

Affected Products

Checkuser Extension
Mediawiki