Description
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin DMCA WaterMarker Cross-Site Scripting (1.0)
WordPress Plugin Responsive Owl Carousel for Elementor Local File Inclusion (1.2.0)
WordPress Plugin YITH WooCommerce Gift Cards Premium Arbitrary File Upload (3.3.0)
UAParser.js Other Vulnerability (CVE-2020-7793)
WordPress Plugin Photo Gallery, Images, Slider in Rbs Image Gallery Security Bypass (2.0.15)