Description
An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes messages were not properly escaped and allowed for users to inject HTML and JavaScript.
Remediation
References
Related Vulnerabilities
ownCloud Improper Access Control Vulnerability (CVE-2016-9467)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6612)
MySQL CVE-2016-3459 Vulnerability (CVE-2016-3459)
MySQL CVE-2022-21368 Vulnerability (CVE-2022-21368)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5338)