Description
An issue was discovered in the ProofreadPage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. XSS can occur via formatNumNoSeparators.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21325 Vulnerability (CVE-2022-21325)
Oracle Database Server CVE-2009-3413 Vulnerability (CVE-2009-3413)
WordPress Plugin ZX_CSV Upload Multiple Vulnerabilities (1)
Roundcube Cross-site Scripting (XSS) Vulnerability (CVE-2015-1433)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-5674)