Description
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Remediation
References
Related Vulnerabilities
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.18)
WordPress Plugin Gettext override translations Cross-Site Scripting (1.0.1)
Play Framework Inadequate Encryption Strength Vulnerability (CVE-2019-17598)
SharePoint Out-of-bounds Write Vulnerability (CVE-2018-0792)
WordPress Plugin wp-easybooking Cross-Site Scripting (1.0.3)