Description
Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9 and 1.23.x before 1.23.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving the multipageimagenavbox class in conjunction with an action=raw value.
Remediation
References
Related Vulnerabilities
WordPress Plugin Slideshow Gallery LITE Multiple Vulnerabilities (1.5.1)
WordPress Plugin Social Media Widget by Acurax Cross-Site Request Forgery (3.2.5)
WordPress Plugin WPS Limit Login Multiple Vulnerabilities (1.4.5)
WordPress Plugin Import any XML or CSV File to WordPress Multiple Vulnerabilities (3.2.4)