Description
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
Remediation
References
Related Vulnerabilities
RubyGems Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1000075)
Oracle Database Server CVE-2006-5342 Vulnerability (CVE-2006-5342)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5324)
WordPress Plugin WP Offload SES Lite Cross-Site Scripting (1.4.4)