Description
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.)
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2015-0479 Vulnerability (CVE-2015-0479)
WordPress Plugin Author Stats Cross-Site Scripting (1.3)
Oracle JRE CVE-2013-5774 Vulnerability (CVE-2013-5774)
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler PHP Object Injection (5.0.0)
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-10752)