CVE-2023-29137
31.03.2023, 19:15
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mediawiki | mediawiki | 𝑥 ≤ 1.39.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration