Description
An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.
Remediation
References
Related Vulnerabilities
WordPress Plugin Product Slider for WooCommerce Security Bypass (2.5.6)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'nggallery-manage-gallery' HTML Injection (0.96)
WordPress Plugin jcwp youtube channel embed Cross-Site Scripting (1.5.2)
WordPress Plugin Simple Events Calendar Multiple Vulnerabilities (1.3.5)