Description
The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revision deletion, suppression, or the hideuser block flag. The vulnerability is fixed in 3.6.4.
Problem types
CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Product status
References
github.com/...eList3/security/advisories/GHSA-7pgw-q3qp-6pgq
github.com/...eList3/security/advisories/GHSA-7pgw-q3qp-6pgq
github.com/...ommit/a3dae0c89fb4214390c29ceffa23bbe2099986d6