Description
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain deleted MediaWiki usernames, related to rev_deleted.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0005)
ownCloud Improper Input Validation Vulnerability (CVE-2014-2585)
TYPO3 Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-26229)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-5394)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-3394)