Description
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social Slider 'rA[]' Parameter SQL Injection (5.6.5)
WordPress Other Vulnerability (CVE-2021-44223)
WordPress Plugin AccessPress Social Icons Cross-Site Scripting (1.6.6)
WordPress Plugin CiviCRM Multiple Cross-Site Scripting Vulnerabilities (5.35.0)
WordPress Plugin Easy Contact Forms Export 'file' Parameter Information Disclosure (1.1.0)