Description
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."
Remediation
References
Related Vulnerabilities
PostgreSQL Improper Certificate Validation Vulnerability (CVE-2021-43766)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2266)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0704)
WordPress Plugin 10Web Social Feed for Instagram Security Bypass (1.3.18)