Description
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
Remediation
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1579)
Internet Information Services Other Vulnerability (CVE-2001-0544)
MySQL CVE-2016-0600 Vulnerability (CVE-2016-0600)
LimeSurvey Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5573)
Atlassian Confluence CVE-2020-29448 Vulnerability (CVE-2020-29448)