CVE-2023-37253 PUBLISHED

Assigner: mitre
Reserved: 29.06.2023 Published: 14.09.2026 Updated: 14.09.2026

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 3.1

Product Status

Vendor MediaWiki
Product ProofreadPage
Versions Default: unaffected
  • affected from 0 to 1.35.11 (excl.)
  • affected from 1.36.0 to 1.38.7 (excl.)
  • affected from 1.39.0 to 1.39.4 (excl.)

References

Problem Types

  • CWE-669 Incorrect Resource Transfer Between Spheres CWE