在 MediaWiki 的 ProofreadPage 扩展(版本至 1.39.3)中发现了一个问题:通过 API 和配置变量泄露了被隐藏用户的敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MediaWiki | ProofreadPage | 0 ~ 1.35.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-23176 | 5.4 MEDIUM | MediaWiki 1.40.2前MassMessage扩展XSS漏洞 |
| CVE-2023-37252 | 3.1 LOW | MediaWiki CheckUser 1.39.3 日志用户名信息泄露 |
No comments yet