Description
An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
Remediation
References
Related Vulnerabilities
MySQL CVE-2023-21980 Vulnerability (CVE-2023-21980)
MySQL CVE-2014-0433 Vulnerability (CVE-2014-0433)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2266)
WordPress Plugin BeCustom Cross-Site Request Forgery (1.0.5.2)
WordPress Plugin Subscriber by BestWebSoft Cross-Site Scripting (1.3.4)