Description
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2020-2800 Vulnerability (CVE-2020-2800)
ColdFusion 8 FCKEditor file upload vulnerability
WordPress Plugin Booking Package-Appointment Booking Calendar System Cross-Site Scripting (1.5.10)
WordPress Plugin Wrapper Link Elementor Malicious Code (1.0.3)
Magento Improper Input Validation Vulnerability (CVE-2021-28585)