4.3

CVE-2023-45362

Exploit

An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak.

Data is provided by the National Vulnerability Database (NVD)
MediawikiMediawiki Version < 1.35.12
MediawikiMediawiki Version >= 1.36.0 < 1.39.5
MediawikiMediawiki Version1.40.0 Update-
MediawikiMediawiki Version1.40.0 Updaterc0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.482
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N