CVE-2020-25813: Medium severity mediawiki vulnerability
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
Other sources
In MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3, Special:UserRights exposes the existence of hidden users.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25813?
CVE-2020-25813 is a medium severity vulnerability that allows exposure of hidden users in MediaWiki.
How do I fix CVE-2020-25813?
To fix CVE-2020-25813, upgrade to MediaWiki versions 1.31.10, 1.34.4, or later.
Which MediaWiki versions are affected by CVE-2020-25813?
CVE-2020-25813 affects MediaWiki versions before 1.31.10 and versions between 1.32.0 and 1.34.3.
What is the impact of CVE-2020-25813 on MediaWiki installations?
CVE-2020-25813 allows unauthorized disclosure of hidden user identities, potentially compromising user privacy.
Is CVE-2020-25813 exploitable remotely?
Yes, CVE-2020-25813 can be exploited remotely by anyone with access to the affected MediaWiki installation.