Description
An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.
Remediation
References
Related Vulnerabilities
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-18650)
MySQL CVE-2019-2752 Vulnerability (CVE-2019-2752)
MySQL CVE-2015-4870 Vulnerability (CVE-2015-4870)
WordPress Plugin My Tickets Cross-Site Scripting (1.5.0)
WordPress Plugin Customer Service Software & Support Ticket System Cross-Site Scripting (5.5.1)