Description
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
Remediation
References
Related Vulnerabilities
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920)
WordPress Plugin NextGEN Gallery-WordPress Gallery Local File Inclusion (2.1.7)
Sqlite Use After Free Vulnerability (CVE-2020-13630)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-25609)
WordPress Plugin Easy Google Analytics for WordPress Cross-Site Request Forgery (1.6.0)