Description
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Mikiurl WordPress Eklentisi Cross-Site Request Forgery (2.0)
Oracle Application Server Incorrect Calculation of Buffer Size Vulnerability (CVE-2004-1363)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-38276)
Jenkins Missing Authorization Vulnerability (CVE-2024-43045)