Description
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Listing, Classified Ads & Business Directory-uListing SQL Injection (2.0.3)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.34)
WordPress Plugin WPS Cleaner Multiple Cross-Site Request Forgery Vulnerabilities (1.4.4)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.5.2.727)
IBM WebSEAL Insertion of Sensitive Information into Log File Vulnerability (CVE-2017-1480)