Description
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
Remediation
References
Related Vulnerabilities
WordPress Plugin Mingle Forum 'edit_post_id' Parameter SQL Injection (1.0.31)
WordPress Plugin WooCommerce BuddyPress Integration Security Bypass (3.2.5)
Oracle Database Server CVE-2019-2571 Vulnerability (CVE-2019-2571)
WordPress Plugin Customer Reviews for WooCommerce Local File Inclusion (5.15.0)
WordPress Plugin Light Messages Cross-Site Request Forgery (1.0)