Description
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2007-3854 Vulnerability (CVE-2007-3854)
WordPress Plugin Comic Book Management System SQL Injection (2.1.0)
Jboss EAP CVE-2017-12189 Vulnerability (CVE-2017-12189)
silverstripeCMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-9280)
WordPress 4.7.x Denial of Service Vulnerability (4.7 - 4.7.9)