Description
An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related query parameters allowed for XSS on certain PageForms-managed MediaWiki pages.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2001-0336)
Envoy Proxy Use After Free Vulnerability (CVE-2024-32974)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2015-2305)
Jenkins Improper Input Validation Vulnerability (CVE-2017-1000394)
MyBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-43281)