ZeroHour

CVE-2022-39193

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p47
Published
()
Modified
Description

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with suppression rights.

Vendors
mediawiki
Products
mediawiki
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.