Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The CleanChanges extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3, when "Group changes by page in recent changes and watchlist" is enabled, allows remote attackers to obtain sensitive information (revision-deleted IPs) via the Recent Changes page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MediaWik CleanChanges扩展信息泄露漏洞
Vulnerability Description
MediaWiki是美国维基媒体(Wikimedia)基金会和MediaWiki志愿者共同开发维护的一套自由免费的基于网络的Wiki引擎,它可用于部署内部的知识管理和内容管理系统。CleanChanges是其中的一个列表扩展,能够隐藏不重要的信息从而使界面更简单。 MediaWiki的CleanChanges扩展中存在信息泄露漏洞,该漏洞源于扩展没有隐藏修改删除的IP地址。远程攻击者可通过Recent Changes页面利用该漏洞获取敏感信息。以下版本受到影响:MediaWiki 1.19.8及之前的版本
CVSS Information
N/A
Vulnerability Type
N/A