Description
An issue was discovered in the ProofreadPage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. XSS can occur via formatNumNoSeparators.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2007-1375)
MySQL CVE-2021-2022 Vulnerability (CVE-2021-2022)
Oracle Application Server CVE-2004-1368 Vulnerability (CVE-2004-1368)
MediaWiki Improper Input Validation Vulnerability (CVE-2014-5243)
Atlassian Jira Missing Authentication for Critical Function Vulnerability (CVE-2019-8449)