Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Out-of-bounds Read Vulnerability (CVE-2017-7668)
WordPress Plugin File Manager Multiple Vulnerabilities (4.8)
WordPress Plugin Quick Contact Form Multiple Vulnerabilities (8.0.3.1)
Liferay DXP Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124)
WordPress Plugin Responsive Image Slider, Photo Gallery And Carousel Security Bypass (1.3.5)