Description
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.
Remediation
References
Related Vulnerabilities
Liferay DXP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-25143)
OpenSSL Improper Input Validation Vulnerability (CVE-2014-3567)
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-32732)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Cross-Site Request Forgery (4.4.2)