Description
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a custom JavaScript file, which is not properly handled when previewing the file.
Remediation
References
Related Vulnerabilities
MongoDb Improper Encoding or Escaping of Output Vulnerability (CVE-2021-20333)
WordPress Plugin Advanced post slider Unspecified Vulnerability (2.4.0)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0704)
Oracle Database Server CVE-2006-5334 Vulnerability (CVE-2006-5334)