MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2017-8810 - Vulnerability Database

MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2017-8810

High
Reference: CVE-2017-8810
Title: MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

MediaWiki before 1.27.4 1.28.x before 1.28.3 and 1.29.x before 1.29.2 when a private wiki is configured provides different error messages for failed login attempts depending on whether the username exists which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests.