Description
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Remediation
References
Related Vulnerabilities
XOOPS CVE-2009-3963 Vulnerability (CVE-2009-3963)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2042)
WordPress Plugin Startklar Elementor Addons Arbitrary File Deletion (1.7.13)
WordPress Plugin Simple Matted Thumbnails Cross-Site Scripting (1.01)
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-14251)