Description
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
Remediation
References
Related Vulnerabilities
WordPress Plugin Similar Posts-Best Related Posts for WordPress Remote Code Execution (3.1.5)
Jetty Observable Discrepancy Vulnerability (CVE-2017-9735)
WordPress Plugin YITH Advanced Refund System for WooCommerce Security Bypass (1.0.10)
WordPress Plugin Ninja Forms with File Uploads Extension Cross-Site Scripting (3.3.12)
concrete5 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-8082)