Description
The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Special:CreatePoll or Special:UpdatePoll.
Remediation
References
Related Vulnerabilities
WordPress Plugin Adicon Server SQL Injection (1.2)
MySQL CVE-2017-3251 Vulnerability (CVE-2017-3251)
Mailman Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-44227)
WordPress Plugin Easy Registration Forms Cross-Site Scripting (2.1.1)
WordPress Plugin Sports Rankings and Lists Cross-Site Scripting (3.5)