Description
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
Remediation
References
Related Vulnerabilities
Atlassian Jira Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-13404)
Dolibarr Incorrect Authorization Vulnerability (CVE-2021-25954)
WordPress Plugin HTML5 jQuery Audio Player Multiple Cross-Site Scripting Vulnerabilities (2.3)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-6624)