Description
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Remediation
References
Related Vulnerabilities
WordPress Plugin Quotes Collection Cross-Site Scripting (2.0.5)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3818)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-1000195)
Oracle Database Server CVE-2015-4794 Vulnerability (CVE-2015-4794)