Description
An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2016-3482 Vulnerability (CVE-2016-3482)
WordPress Plugin WP eCommerce 'cart_messages[]' Parameter Cross-Site Scripting (3.8.6)
WordPress Plugin GN Publisher: Google News Compatible RSS Feeds Cross-Site Scripting (1.5.5)
WordPress Plugin ByREV WP-PICShield Cross-Site Request Forgery (1.9.7)