Description
Cross-site scripting (XSS) vulnerability in the preview in the TemplateSandbox extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via the text parameter to Special:TemplateSandbox.
Remediation
References
Related Vulnerabilities
WordPress Plugin Awesome Support-WordPress HelpDesk & Support Unspecified Vulnerability (6.0.7)
Moodle CVE-2021-36394 Vulnerability (CVE-2021-36394)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0738)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1591)