Description
An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.
Remediation
References
Related Vulnerabilities
WordPress Plugin Membership Simplified Arbitrary File Download (1.58)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9033)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2006-4343)
Oracle Database Server CVE-2023-21949 Vulnerability (CVE-2023-21949)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2042)