Description
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Remediation
References
Related Vulnerabilities
WordPress Plugin Cool Tag Cloud Cross-Site Scripting (2.25)
WordPress Plugin Elementor Website Builder Security Bypass (2.9.5)
WordPress Plugin WooSidebars Cross-Site Scripting (1.4.1)
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26271)
Oracle Database Server CVE-2015-0455 Vulnerability (CVE-2015-0455)