Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:October.
Remediation
References
Related Vulnerabilities
WordPress Plugin Redux Framework Cross-Site Request Forgery (4.1.20)
IBM WebSEAL URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-4153)
WordPress Plugin WPMK Ajax Finder Cross-Site Request Forgery (1.0.1)
Drupal Core 6.x Cross-Site Scripting (6.0 - 6.10)
WordPress Plugin WP Photo Album Plus Cross-Site Request Forgery (4.8.11)