Vulnerabilities > CVE-2020-35624 - Information Exposure Through Discrepancy vulnerability in Mediawiki

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
mediawiki
CWE-203

Summary

An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.

Vulnerable Configurations

Part Description Count
Application
Mediawiki
378

Common Weakness Enumeration (CWE)