MediaWiki Insecure Storage of Sensitive Information Vulnerability - CVE-2021-36127 - Vulnerability Database

MediaWiki Insecure Storage of Sensitive Information Vulnerability - CVE-2021-36127

Medium
Reference: CVE-2021-36127
Title: MediaWiki Insecure Storage of Sensitive Information Vulnerability
Overview:

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which for a suppressed MediaWiki user were different than for any other user thus easily disclosing suppressed accounts (which are supposed to be completely hidden).