Description
Cross-site scripting (XSS) vulnerability in profileinfo.php in MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
Remediation
References
Related Vulnerabilities
e107 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2020)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-15901)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-3065)
OpenSSL Improper Certificate Validation Vulnerability (CVE-2023-0465)