Description
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
Remediation
References
Related Vulnerabilities
WordPress Plugin smart Archive Page Remove Unspecified Vulnerability (3)
WordPress Plugin Thank You Counter Button Multiple Cross-Site Scripting Vulnerabilities (1.8.7)
Apache HTTP Server Other Vulnerability (CVE-2002-0843)
Squid Improper Input Validation Vulnerability (CVE-2014-0128)
WordPress Plugin UserPro-Community and User Profile Multiple Vulnerabilities (5.1.4)