Description
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
Remediation
References
Related Vulnerabilities
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.17)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-7859)
MySQL CVE-2021-35618 Vulnerability (CVE-2021-35618)
PHP Improper Encoding or Escaping of Output Vulnerability (CVE-2024-5585)
WordPress Plugin Gallery by BestWebSoft Cross-Site Scripting (4.2.1)