An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppressed accounts (which are supposed to be completely hidden).
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | * | 1.36 (including) |