Description
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
Remediation
References
Related Vulnerabilities
WordPress Plugin Post Grid PHP Object Injection (2.0.11)
Ruby on Rails Uncontrolled Resource Consumption Vulnerability (CVE-2020-8185)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Security Bypass (3.0.1)
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-3661)