Description
An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion text (a parameter to mediasearch-did-you-mean) was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the intitle: search operator within the query.
Remediation
References
Related Vulnerabilities
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1886)
Drupal Core 7.x Remote Code Execution (7.0 - 7.74)
WordPress Plugin WP Affiliate Platform Multiple Vulnerabilities (6.3.9)
WordPress Plugin Billplz for WooCommerce Unspecified Vulnerability (3.10)
WordPress Plugin A to Z Category Listing 'R' Parameter SQL Injection (1.3)