Description
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.
Remediation
References
Related Vulnerabilities
Django DEPRECATED: Code Vulnerability (CVE-2015-0222)
WordPress Plugin Thrive Ovation Security Bypass (2.4.4)
MySQL CVE-2014-2436 Vulnerability (CVE-2014-2436)
Ruby on Rails CVE-2021-22902 Vulnerability (CVE-2021-22902)
WordPress Plugin Wow Forms-create any form with custom style SQL Injection (3.1.3)