Description
An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.
Remediation
References
Related Vulnerabilities
Elgg URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-11016)
WordPress Plugin Responsive Slider-Image Slider-Slideshow for WordPress SQL Injection (2.6.8)
WordPress Plugin Pressbooks Cross-Site Scripting (2.4.2)
Joomla Incorrect Authorization Vulnerability (CVE-2021-26027)
WordPress Plugin WooCommerce Possible Remote Code Execution (3.4.5)