Description
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-14672 Vulnerability (CVE-2020-14672)
MySQL Improper Privilege Management Vulnerability (CVE-2017-3257)
WordPress Plugin Facebook Button by BestWebSoft Cross-Site Scripting (2.33)
WordPress Plugin MW WP Form Cross-Site Scripting (1.7.1)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-0213)