Description
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain deleted MediaWiki usernames, related to rev_deleted.
Remediation
References
Related Vulnerabilities
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-1581)
Joomla Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-5671)
WordPress Plugin Catch Themes Demo Import Unspecified Vulnerability (1.8)
WordPress Plugin WordPress Connect Cross-Site Scripting (2.0.3)
Oracle Database Server CVE-2014-4292 Vulnerability (CVE-2014-4292)