Description
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2911 Vulnerability (CVE-2019-2911)
IBM RTC Cross-site Scripting (XSS) Vulnerability (CVE-2020-4697)
WordPress Plugin Button Widget Smartsoft Cross-Site Request Forgery (1.0.1)
WordPress Plugin ToolPage Cross-Site Scripting (1.6.1)
WordPress Plugin Daily Inspiration Generator Open Redirect (2.0)