Description
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function was not being properly escaped, allowing for XSS under certain conditions.
Remediation
References
Related Vulnerabilities
WordPress Plugin FreshMail For WordPress Multiple SQL Injection Vulnerabilities (1.5.8)
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Cross-Site Scripting (1.16.10)
WebLogic CVE-2020-2828 Vulnerability (CVE-2020-2828)
IBMHttpServer Improper Input Validation Vulnerability (CVE-2023-26281)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-39193)