Description
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.6.x Information Disclosure (1.6.0 - 1.6.3)
concrete5 Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-13790)
WordPress Plugin File Manager Information Disclosure (6.4)
PHP Out-of-bounds Read Vulnerability (CVE-2020-7060)
WordPress Plugin Asgaros Forum Multiple SQL Injection Vulnerabilities (1.15.12)