Description
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
Remediation
References
Related Vulnerabilities
Rukovoditel Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11817)
WordPress Plugin WP Booking Cross-Site Scripting (1.4)
WordPress Plugin JupiterX Core Multiple Vulnerabilities (2.0.6)
MySQL CVE-2012-0113 Vulnerability (CVE-2012-0113)
Moodle Resource Management Errors Vulnerability (CVE-2015-5332)