High severity7.5NVD Advisory· Published Apr 21, 2020· Updated Jun 17, 2026
CVE-2020-12051
CVE-2020-12051
Description
The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In other words, the information can be retrieved via the action API even though access would be denied when simply visiting wiki/Special:CentralAuth in a web browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- MediaWiki/CentralAuth extensiondescription
- Range: <=REL1_34
- osv-coords
Patches
Vulnerability mechanics
References
2- phabricator.wikimedia.org/T250594nvdPatchVendor Advisory
- gerrit.wikimedia.org/r/nvdVendor Advisory
News mentions
0No linked articles in our index yet.