4.3
CVSSv3

CVE-2021-30153

Published: 15/04/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in the VisualEditor extension in MediaWiki prior to 1.31.13, and 1.32.x up to and including 1.35.x prior to 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

Vendor Advisories

An issue was discovered in MediaWiki before 13112 and 132x through 135x before 1352 ApiVisualEditor leaked information about hidden users ...