Description
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.
Remediation
References
Related Vulnerabilities
Envoy Proxy Reachable Assertion Vulnerability (CVE-2021-29258)
WordPress Plugin WP Limit Login Attempts SQL Injection (2.0.0)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2010-3933)
Zope Web Application Server Other Vulnerability (CVE-2002-0688)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2017-3169)