Description
An issue was discovered in the CommentBox extension for MediaWiki through 1.35.2. Via crafted configuration variables, a malicious actor could introduce XSS payloads into various layers.
Remediation
References
Related Vulnerabilities
WordPress Plugin Thrive Clever Widgets Security Bypass (1.56)
TYPO3 CVE-2023-38499 Vulnerability (CVE-2023-38499)
MySQL CVE-2021-2122 Vulnerability (CVE-2021-2122)
PHP Resource Management Errors Vulnerability (CVE-2002-2309)
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5965)