Description
Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid username.
Remediation
References
Related Vulnerabilities
WordPress Plugin ALO EasyMail Newsletter Cross-Site Request Forgery (2.9.2)
MySQL Improper Input Validation Vulnerability (CVE-2017-3273)
Apache Tomcat Other Vulnerability (CVE-2000-0759)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.36)
Wordpress Plugin Backup Migration CVE-2023-6553 Vulnerability (CVE-2023-6553)