CVE-2020-25813Sensitive Information Exposure in Mediawiki

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 41.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateMay 24

Description

In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

Packagistmediawiki/core1.31.01.31.9+1
debiandebian/mediawiki< mediawiki 1:1.35.0-1 (bookworm)
NVDmediawiki/mediawiki1.32.01.34.4+1
Debianmediawiki/mediawiki< 1:1.35.0-1+3

Also affects: Fedora 33

🔴Vulnerability Details

3
OSV
MediaWiki Special:UserRights exposes the existence of hidden users2022-05-24
GHSA
MediaWiki Special:UserRights exposes the existence of hidden users2022-05-24
OSV
CVE-2020-25813: In MediaWiki before 12020-09-27

📋Vendor Advisories

2
Red Hat
mediawiki: Special: UserRights exposes the existence of hidden users2020-09-27
Debian
CVE-2020-25813: mediawiki - In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:Use...2020
CVE-2020-25813 — Sensitive Information Exposure | cvebase