MediaWiki prior to 1.18.5, and 1.19.x prior to 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mediawiki mediawiki 1.19.0 |
||
mediawiki mediawiki |
||
mediawiki mediawiki 1.19.1 |