Description
Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2014-6545 Vulnerability (CVE-2014-6545)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0714)
WordPress Plugin Theme Blvd Widget Areas Multiple Security Bypass Vulnerabilities (1.2.2)
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-8663)