Description
Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php.
Remediation
References
Related Vulnerabilities
b2evolution URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-22840)
Oracle JRE CVE-2013-0437 Vulnerability (CVE-2013-0437)
Joomla CVE-2018-17856 Vulnerability (CVE-2018-17856)
TYPO3 Improper Input Validation Vulnerability (CVE-2013-7079)
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499)