Description
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.
Remediation
References
Related Vulnerabilities
WordPress Plugin SRS Simple Hits Counter SQL Injection (1.0.4)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9514)
Joomla! Core 1.7.0 Cross-Site Scripting (1.7.0)
WordPress Plugin Google Analytics Dashboard Multiple Unspecified Vulnerabilities (2.0.5)
JBoss Application Server Directory Traversal Vulnerability (CVE-2006-5750)