Description
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.
References
https://phabricator.wikimedia.org/T327613
Issue TrackingPatch
https://phabricator.wikimedia.org/T327613
Issue TrackingPatch
Weaknesses
Primary
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-284
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2023-03-31T17:15:07.503Z
2 years agoLast modified
2025-02-18T15:15:15.893Z
1 year ago