Description
An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.
Remediation
References
Related Vulnerabilities
WordPress Plugin Side Menu Lite-add sticky fixed buttons SQL Injection (2.2.5)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.26)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-14725)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-39193)