Information disclosure in MediaWiki - CVE-2021-31545
Published: April 26, 2021
MediaWiki
MediaWiki.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in the AbuseFilter extension due to the page_recent_contributors leaked the existence of certain deleted MediaWiki usernames, related to rev_deleted. A remote attacker can gain unauthorized access to sensitive information on the system.