Description
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3427)
Atlassian Confluence Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-6342)
WordPress Plugin WP Photo Album 'photo' Parameter SQL Injection (1.0)
WordPress Plugin WordPress Payments-GetPaid Cross-Site Scripting (2.3.3)
Atlassian Confluence Uncontrolled Search Path Element Vulnerability (CVE-2021-43940)