Description
Cross-site scripting (XSS) vulnerability in profileinfo.php in MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
Remediation
References
Related Vulnerabilities
MediaWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-10959)
Joomla! Core 1.0.x Cross-Site Scripting (1.0.0 - 1.0.15)
WordPress Plugin NextGEN Gallery-WordPress Gallery Arbitrary File Upload (1.9.12)
WordPress Plugin Easy PayPal Buy Now Button Multiple Vulnerabilities (1.7.2)