CVE Vulnerabilities

CVE-2023-29140

Published: Mar 31, 2023 | Modified: Apr 11, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.39.3 (including)

References