Description
An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could easily propagate across many pages for many users.
Remediation
References
Related Vulnerabilities
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more PHAR Deserialization (2.9.8.5)
OpenSSL Improper Certificate Validation Vulnerability (CVE-2019-1552)
WordPress Plugin WP Private Messages SQL Injection (1.0.1)
SharePoint Out-of-bounds Read Vulnerability (CVE-2020-1342)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4298)