Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29140


An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.


Published

2023-03-31T19:15:07.503

Last Modified

2025-02-18T16:15:15.893

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mediawiki mediawiki ≤ 1.39.3 Yes

References