An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.
References
Link | Resource |
---|---|
https://phabricator.wikimedia.org/T327613 | Issue Tracking Patch |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-03-31T00:00:00
Updated: 2023-03-31T00:00:00
Reserved: 2023-03-31T00:00:00
Link: CVE-2023-29140
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-03-31T19:15:07.503
Modified: 2023-04-11T06:08:23.753
Link: CVE-2023-29140
JSON object: View
Redhat Information
No data.
CWE