Description
An issue was discovered in the Mentor dashboard in the GrowthExperiments extension in MediaWiki through 1.36.2. The Growthexperiments-mentor-dashboard-mentee-overview-add-filter-total-edits-headline, growthexperiments-mentor-dashboard-mentee-overview-add-filter-starred-headline, growthexperiments-mentor-dashboard-mentee-overview-info-text, growthexperiments-mentor-dashboard-mentee-overview-info-legend-headline, and growthexperiments-mentor-dashboard-mentee-overview-active-ago MediaWiki messages were not being properly sanitized and allowed for the injection and execution of HTML and JavaScript.
Remediation
References
Related Vulnerabilities
WordPress Plugin YAWPP (Yet Another WordPress Petition Plugin) SQL Injection (1.2)
WordPress Plugin AP Companion includes Backdoor [Only if downloaded via the vendor website] (1.0.6)
Apache HTTP Server Other Vulnerability (CVE-2004-1082)
Django Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0472)