Information Disclosure of Suppressed Usernames via User ID Lookup in MediaWiki

Information Disclosure of Suppressed Usernames via User ID Lookup in MediaWiki

CVE-2019-16738 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.

Learn more about our User Device Pen Test.