Description
An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related query parameters allowed for XSS on certain PageForms-managed MediaWiki pages.
Remediation
References
Related Vulnerabilities
OpenSSL Access of Resource Using Incompatible Type ('Type Confusion') Vulnerability (CVE-2023-0286)
WordPress Plugin StoryChief Cross-Site Scripting (1.0.30)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6106)
Magento Incorrect Authorization Vulnerability (CVE-2021-28567)