CVE-2013-6472 Information

Description

MediaWiki before 1.19.10 1.2x before 1.21.4 and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) log API (2) enhanced RecentChanges and (3) user watchlists.

Reference

http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-January/000138.html

Share on: