Description
An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The growthexperiments-edit-config-error-invalid-title MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript.
Remediation
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2007-3543)
WordPress Plugin WP Reroute Email SQL Injection (1.4.6)
Envoy Proxy Incomplete Cleanup Vulnerability (CVE-2023-35945)
WordPress Plugin ComicPress Manager 'lang' Parameter Cross-Site Scripting (1.4.9.9)
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Cross-Site Scripting (1.16.4)