Description
An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes messages were not properly escaped and allowed for users to inject HTML and JavaScript.
Remediation
References
Related Vulnerabilities
Moodle Improper Input Validation Vulnerability (CVE-2011-4302)
WordPress Plugin Stock market charts from finviz Cross-Site Scripting (1.0)
PostgreSQL Other Vulnerability (CVE-2004-0547)
WordPress 5.7.x Multiple Vulnerabilities (5.7 - 5.7.10)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3190)