Description
In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.
Remediation
References
Related Vulnerabilities
WordPress Plugin Qwizcards-online quizzes and flashcards Cross-Site Scripting (3.36)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-10968)
Dolibarr Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-0819)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7834)