#VU14826 Improper access control in MediaWiki - CVE-2018-0504
Published: September 21, 2018
MediaWiki
MediaWiki.org
Description
The vulnerability allows a remote authenticated attacker to gain access to sensitive information.
The vulnerability exists due to incorrect validation of user privileges when log event is partially hidden. A remote authenticated attacker can access sensitive information from the log event via the 'Special:Redirect/logid' function.