Description
An issue was discovered in SecurePoll in the Growth extension in MediaWiki through 1.36.2. Simple polls allow users to create alerts by changing their User-Agent HTTP header and submitting a vote.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2014-6545 Vulnerability (CVE-2014-6545)
WordPress Plugin Updater by BestWebSoft Cross-Site Scripting (1.34)
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker SQL Injection (7.3.4)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2011-4415)