Description
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
Remediation
References
Related Vulnerabilities
Jenkins Missing Authorization Vulnerability (CVE-2021-21685)
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.5)
WordPress Plugin WP Forum Server Multiple SQL Injection (1.6.5)
Elgg Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6563)
WordPress Plugin Link Juice Keeper Cross-Site Scripting (2.0.2)