Description
An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related query parameters allowed for XSS on certain PageForms-managed MediaWiki pages.
Remediation
References
Related Vulnerabilities
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2018-1302)
WordPress Plugin OAuth client Single Sign On for WordPress (OAuth 2.0 SSO) Security Bypass (3.0.3)
Oracle JRE CVE-2013-2456 Vulnerability (CVE-2013-2456)
Drupal Improper Access Control Vulnerability (CVE-2016-5385)
WordPress Plugin Custom Permalinks Unspecified Vulnerability (0.7.15)