CVE-2015-8007

The Echo extension for MediWiki does not properly implement the hideuser functionality, which allows remote authenticated users to see hidden usernames in "non-revision based" notifications, as demonstrated by viewing a hidden username in a Thanks notification.

Date published : 2015-11-09

https://phabricator.wikimedia.org/T110553

https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000182.html