Description
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
Remediation
References
Related Vulnerabilities
WordPress Plugin Duplicator-WordPress Migration Arbitrary File Disclosure (0.3.0)
WordPress Plugin Contact Form 7 Database Addon-CFDB7 Unspecified Vulnerability (1.2.5.7)
TYPO3 Files or Directories Accessible to External Parties Vulnerability (CVE-2021-21355)
WordPress Plugin Inline Gallery 'do' Parameter Cross-Site Scripting (0.3.9)