PT-2023-25891 · Mediawiki+1 · Mediawiki+2

Dreamy_Jazz

·

Published

2023-06-30

·

Updated

2024-11-27

·

CVE-2023-37300

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki CheckUser extension versions through 1.39.3
Description An issue was discovered in the "CheckUserLog API" in the CheckUser extension for MediaWiki. There is incorrect access control for visibility of hidden users.
Recommendations For MediaWiki CheckUser extension versions through 1.39.3, update to a version that contains a fix for this issue.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-37300
CVE-2023-37300

Affected Products

Alt Linux
Checkuser Extension
Mediawiki