Description
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Fast Velocity Minify Information Disclosure (2.7.6)
phpMyAdmin Other Vulnerability (CVE-2006-5116)
Oracle JRE CVE-2013-2470 Vulnerability (CVE-2013-2470)
WordPress Plugin Smart Forms-when you need more than just a contact form Security Bypass (2.6.84)
WordPress Plugin Flickr Gallery PHP Object Injection (1.5.2)