Description
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."
Remediation
References
Related Vulnerabilities
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-4391)
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-13376)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.1.9)
Moodle Improper Following of Specification by Caller Vulnerability (CVE-2019-14829)
WordPress Plugin Carousel slideshow Arbitrary File Upload (3.11)