Description
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
Remediation
References
Related Vulnerabilities
WordPress Plugin Blue Wrench Video Widget Cross-Site Request Forgery (1.0.5)
Magento Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-9588)
Squid Improper Input Validation Vulnerability (CVE-2021-31808)
WordPress Plugin Import Spreadsheets from Microsoft Excel Arbitrary File Upload (10.1.4)