Description
An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.
Remediation
References
Related Vulnerabilities
WordPress Plugin AI ChatBot Arbitrary File Deletion (4.9.2)
Opencart Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2023-40834)
Oracle Database Server CVE-2011-0877 Vulnerability (CVE-2011-0877)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4283)