Description
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.)
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-2174 Vulnerability (CVE-2021-2174)
Oracle Application Server Other Vulnerability (CVE-2002-0559)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977)
Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1614)