Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
Remediation
References
Related Vulnerabilities
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.3)
WordPress Plugin Import all XML, CSV & TXT into WordPress Information Disclosure (3.6.74)
WordPress Plugin WP No External Links Cross-Site Scripting (3.5.18)
Jboss EAP Configuration Vulnerability (CVE-2008-3519)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2016-2161)