Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
Remediation
References
Related Vulnerabilities
AbanteCart Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26521)
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-7913)
WordPress Other Vulnerability (CVE-2007-1409)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-5104)