CVE-2023-37300
MEDIUM5.3EPSS 0.26%Published: 3/6/2024Modified: 4/3/2025
Description
An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.
Affected packages (1)
- Bitnami/mediawikifrom 0, < 1.39.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |