Description
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
Remediation
References
Related Vulnerabilities
WordPress 5.0.x PHP Object Injection (5.0 - 5.0.12)
Oracle Database Server CVE-2012-0526 Vulnerability (CVE-2012-0526)
CKEditor Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2021-26271)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4584)
TYPO3 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-3633)