Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:October.
Remediation
References
Related Vulnerabilities
Microsoft SQL Server Other Vulnerability (CVE-2001-0344)
WordPress Plugin Import any XML or CSV File to WordPress Cross-Site Scripting (3.4.6)
WordPress Plugin FancyBox for WordPress Cross-Site Scripting (3.0.2)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (3.9.7)