CVE-2015-8007

Publication date

2015-11-09 18:00:00

Family

mitre

State

PUBLISHED

Description

The Echo extension for MediWiki does not properly implement the hideuser functionality, which allows remote authenticated users to see hidden usernames in "non-revision based" notifications, as demonstrated by viewing a hidden username in a Thanks notification.