Description
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Related Posts for WordPress Cross-Site Scripting (2.0.3)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7837)
WordPress Plugin Import any XML or CSV File to WordPress Arbitrary File Upload (3.6.7)
Squid Improper Input Validation Vulnerability (CVE-2016-4555)
WordPress 7PK - Security Features Vulnerability (CVE-2014-9039)