Description
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.
Remediation
References
Related Vulnerabilities
ownCloud Other Vulnerability (CVE-2012-4389)
PHP Other Vulnerability (CVE-2007-1718)
WordPress Plugin Catchers Helpdesk and Ticket system for Support Cross-Site Scripting (1.0.3)
Oracle Database Server CVE-2008-2607 Vulnerability (CVE-2008-2607)
WordPress Plugin Image Gallery-Responsive Photo Gallery SQL Injection (1.8.9)