Description
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Remediation
References
Related Vulnerabilities
Envoy Proxy Improper Certificate Validation Vulnerability (CVE-2022-21657)
WordPress Plugin JVM WooCommerce Wishlist Unspecified Vulnerability (1.2.6)
OpenSSL Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3207)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2199)