Description
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Remediation
References
Related Vulnerabilities
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-44040)
WordPress Plugin Wordable Security Bypass (3.1.1)
WordPress Plugin User Login Log Cross-Site Scripting (2.2.2)
WebLogic Other Vulnerability (CVE-2020-10672)
WordPress Plugin Elementor Addon Elements Cross-Site Request Forgery (1.6.3)