Description
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
Remediation
References
Related Vulnerabilities
WebLogic Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-8908)
Oracle JRE CVE-2022-21628 Vulnerability (CVE-2022-21628)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0734)
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker SQL Injection (7.3.4)
WordPress Multiple Cross-Site Scripting Vulnerabilities (1.2 - 1.2.1)