PT-2023-13711 · Mediawiki · Mediawiki Checkuser Extension

Dreamy_Jazz

·

Published

2023-01-20

·

Updated

2024-03-06

·

CVE-2022-39193

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki CheckUser extension versions through 1.39.x
Description An issue in the CheckUser extension for MediaWiki exposes information on the performer of edits and logged actions, which should only be viewable by users with suppression or checkuser rights.
Recommendations For MediaWiki CheckUser extension versions through 1.39.x, restrict access to components that expose sensitive information to users with suppression or checkuser rights until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
BIT-MEDIAWIKI-2022-39193
CVE-2022-39193

Affected Products

Mediawiki Checkuser Extension