Description
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and summaries, from AbuseLog revision data. This affects REL1_32 and REL1_33.
References (4)
Core 4
Core References
Permissions Required x_refsource_misc
https://phabricator.wikimedia.org/T224203
Patch x_refsource_misc
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/538051/
Patch x_refsource_misc
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/538053/
Patch x_refsource_misc
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/538054/
Scores
CVSS v3
7.5
EPSS
0.0047
EPSS Percentile
64.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-532
Status
published
Products (2)
mediawiki/abusefilter
1.32
mediawiki/abusefilter
1.33
Published
Mar 20, 2020
Tracked Since
Feb 18, 2026