Description
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
Remediation
References
Related Vulnerabilities
Oracle Database Server Other Vulnerability (CVE-2005-3206)
WordPress 3.3.1 Multiple Vulnerabilities (2.0 - 3.3.1)
WordPress Plugin WP Code Highlight.js Cross-Site Request Forgery (0.6.2)
Internet Information Services Other Vulnerability (CVE-1999-1148)
WordPress Plugin Welcart e-Commerce PHP Object Injection (1.9.3)