Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
Remediation
References
Related Vulnerabilities
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-19594)
WordPress Plugin Really Simple Guest Post Local File Inclusion (1.0.6)
WordPress Plugin No Follow All External Links Spam Injection (2.3.0)
WordPress Plugin Stylish Price List Security Bypass (6.9.0)
WordPress Plugin Meow Gallery (+ Gallery Block) Security Bypass (4.1.9)