Description
Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php.
Remediation
References
Related Vulnerabilities
WordPress 4.5.x Cross-Domain Flash Injection Vulnerability (4.5 - 4.5.12)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1453)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-17189)
Oracle JRE CVE-2013-5787 Vulnerability (CVE-2013-5787)
Roundcube Cross-site Scripting (XSS) Vulnerability (CVE-2015-8793)