Description
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
Remediation
References
Related Vulnerabilities
WebLogic CVE-2020-2801 Vulnerability (CVE-2020-2801)
WordPress Plugin QueryWall:Plug'n Play Firewall Cross-Site Scripting (1.1.0)
Riot.js Resource Management Errors Vulnerability (CVE-2016-10527)
MySQL CVE-2021-2352 Vulnerability (CVE-2021-2352)
WordPress Plugin Master Slider-Responsive Touch Slider Cross-Site Scripting (2.7.1)