Description
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function was not being properly escaped, allowing for XSS under certain conditions.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2695 Vulnerability (CVE-2019-2695)
WordPress Plugin Live Chat Unlimited Cross-Site Scripting (2.8.3)
WordPress Plugin oQey Gallery 'gal_id' Parameter SQL Injection (0.4.8)
MediaWiki Resource Management Errors Vulnerability (CVE-2015-6733)
WordPress Improper Authentication Vulnerability (CVE-2014-0166)