Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3180)
Play Framework Inadequate Encryption Strength Vulnerability (CVE-2019-17598)
WordPress Plugin Ultimate Appointment Booking & Scheduling Unspecified Vulnerability (1.1.10)
WordPress Uncontrolled Resource Consumption Vulnerability (CVE-2018-6389)
WordPress Plugin SMTP Mailer Cross-Site Request Forgery (1.0.6)