Description
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
Remediation
References
Related Vulnerabilities
SharePoint Out-of-bounds Write Vulnerability (CVE-2014-1761)
Opencart Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3990)
WordPress Plugin Contact Form by ContactMe.com Cross-Site Scripting (2.3)
MySQL CVE-2018-2759 Vulnerability (CVE-2018-2759)
WordPress Plugin AVH Extended Categories Widgets SQL Injection (4.0.0)