Description
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.
Remediation
References
Related Vulnerabilities
WordPress Plugin Theme Blvd Widget Areas Multiple Security Bypass Vulnerabilities (1.2.2)
PrestaShop Improper Privilege Management Vulnerability (CVE-2023-43664)
WordPress Plugin WP Activity Log Cross-Site Request Forgery (4.1.3.2)
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler SQL Injection (6.3.0)