Description
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
Remediation
References
Related Vulnerabilities
Liferay DXP Incorrect Authorization Vulnerability (CVE-2024-25604)
Roundcube Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-19205)
WordPress Plugin Contact Form by Supsystic Cross-Site Scripting (1.7.19)
OpenSSL Improper Authentication Vulnerability (CVE-2009-0653)