Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential information (e.g., IP addresses and User-Agent headers for election traffic) on a testwiki SecurePoll instance.
Remediation
References
Related Vulnerabilities
Jboss EAP Cryptographic Issues Vulnerability (CVE-2013-1921)
Oracle Database Server CVE-2011-3512 Vulnerability (CVE-2011-3512)
WordPress Plugin Booking calendar, Appointment Booking System Security Bypass (2.2.2)
WordPress Plugin Backend Localization Multiple Cross-Site Scripting Vulnerabilities (1.6.1)
WordPress Plugin Ultimate Membership Pro Cross-Site Request Forgery (8.6.2)