Description
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppressed accounts (which are supposed to be completely hidden).
Remediation
References
Related Vulnerabilities
WordPress 4.2.x Cross-Site Scripting Vulnerability (4.2 - 4.2.5)
MySQL Uncontrolled Resource Consumption Vulnerability (CVE-2020-11080)
CubeCart Session Fixation Vulnerability (CVE-2021-33394)
WordPress Plugin FormCraft-Contact Form Builder Cross-Site Request Forgery (1.2.1)
WordPress Plugin WordPress Geo-CF Geo Cross-Site Scripting (7.13.11)