Description
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)
Remediation
References
Related Vulnerabilities
Joomla! Core 1.5.x Information Disclosure (1.5.0 - 1.5.12)
CakePHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3712)
WordPress Plugin WP Live.php 's' Parameter Cross-Site Scripting (1.2.1)
WordPress Plugin WordPress Gallery MaxGalleria Unspecified Vulnerability (6.0.8)