Description
Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Google Maps Unspecified Vulnerability (6.2.1)
PostgreSQL Improper Input Validation Vulnerability (CVE-2019-10210)
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977)
IBM WebSEAL Insufficiently Protected Credentials Vulnerability (CVE-2021-20439)