Medium severity4.3NVD Advisory· Published Apr 15, 2023· Updated Jun 17, 2026
CVE-2021-30153
CVE-2021-30153
Description
An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- MediaWiki/VisualEditor extensiondescription
- Range: <1.31.13, 1.32.x through 1.35.x before 1.35.2
Patches
Vulnerability mechanics
References
3- lists.wikimedia.org/pipermail/wikitech-l/2021-April/094418.htmlnvdMailing ListPatchVendor Advisory
- phabricator.wikimedia.org/T270453nvdExploitVendor Advisory
- lists.wikimedia.org/hyperkitty/list/wikitech-l%40lists.wikimedia.org/message/XYBF5RSTJRMVCP7QBYK7643W75A3KCIY/nvd
News mentions
0No linked articles in our index yet.