In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mediawiki/core(Packagist) | 1.31.0 | 1.31.4 | N/A |
| mediawiki/core(Packagist) | 1.32.0 | 1.32.4 | N/A |
| mediawiki/core(Packagist) | 1.33.0 | 1.33.1 | N/A |
CVSS Metrics