Description
An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.
Remediation
References
Related Vulnerabilities
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20405)
Zope Web Application Server Resource Management Errors Vulnerability (CVE-2008-5102)
WordPress Plugin FileBird-WordPress Media Library Folders & File Manager Cross-Site Scripting (2.4)
WordPress Plugin Flipbox Builder PHP Object Injection (1.5)
WordPress Plugin KN Fix Your Title Cross-Site Scripting (1.0.1)