Description
In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.
Remediation
References
Related Vulnerabilities
WordPress Plugin Image Photo Gallery Final Tiles Grid Security Bypass (3.3.52)
MySQL CVE-2022-21278 Vulnerability (CVE-2022-21278)
WordPress Plugin Backup and Restore WordPress-WPBackItUp Cross-Site Request Forgery (1.6.7)
WordPress Plugin Apptivo eCommerce Multiple Cross-Site Scripting Vulnerabilities (1.1.5)