Description
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Shieldon-WordPress Firewall Cross-Site Scripting (1.6.3)
Joomla! Core 1.5.x Information Disclosure (1.5.0 - 1.5.25)
Java Unspesificed Vulnerability (CVE-2020-14803)
Python Uncontrolled Resource Consumption Vulnerability (CVE-2020-14422)
WordPress Plugin Two Way CHAT-Send or receive messages to your user Multiple Vulnerabilities (3.1.4)