Description
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2007-4887)
Oracle Database Server CVE-2006-0291 Vulnerability (CVE-2006-0291)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1963)
Oracle JRE CVE-2024-21235 Vulnerability (CVE-2024-21235)
osCommerce Incorrect Comparison Vulnerability (CVE-2020-23360)