Description
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2008-2607 Vulnerability (CVE-2008-2607)
WordPress Plugin Markup (JSON-LD) structured in schema.org Cross-Site Scripting (4.8.1)
WordPress Plugin moreAds SE Cross-Site Scripting (1.4.6)
LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-16177)
WordPress Plugin Modula Image Gallery Cross-Site Scripting (1.3.5)