Description
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.
References
https://phabricator.wikimedia.org/T327613
Issue TrackingPatch
https://phabricator.wikimedia.org/T327613
Issue TrackingPatch
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2023-03-31T19:15:07.503
2 years agoLast modified
2025-02-18T16:15:15.893
4 months ago