PT-2023-25896 · Mediawiki+1 · Mediawiki Proofreadpage Extension+1

Soda

·

Published

2023-06-30

·

Updated

2024-11-26

·

CVE-2023-37305

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki ProofreadPage extension versions through 1.39.3
Description An issue in the ProofreadPage extension for MediaWiki allows hidden users to be exposed via public interfaces, specifically in the includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php files.
Recommendations For versions through 1.39.3, consider restricting access to the PageContentHandler and PageDisplayHandler classes until a patch is available. As a temporary workaround, review the configuration of public interfaces to minimize the exposure of hidden users. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-37305
CVE-2023-37305

Affected Products

Alt Linux
Mediawiki Proofreadpage Extension