Description
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
Remediation
References
Related Vulnerabilities
WordPress Plugin Nmedia MailChimp Widget 'abs_path' Parameter Remote File Include (3.1)
WordPress Plugin GD Star Rating 'votes' Parameter SQL Injection (1.9.8)
WordPress Plugin Post Type Switcher Multiple Unspecified Vulnerabilities (1.5.0)
WordPress Plugin Role Scoper Cross-Site Scripting (1.3.64)
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-1000484)