Description
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.
Remediation
References
Related Vulnerabilities
WordPress Plugin Estatik Real Estate Arbitrary File Upload (2.2.5)
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1336)
WordPress Plugin LearnPress-WordPress LMS Multiple Vulnerabilities (3.0.12)
WordPress Plugin Video Lessons Manager-Best Video Course LMS Cross-Site Scripting (1.7.1)