Description
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2019-2618 Vulnerability (CVE-2019-2618)
WordPress Plugin MiwoEvents-Manage & Book Events Unspecified Vulnerability (1.2.0)
Oracle Database Server CVE-2020-2510 Vulnerability (CVE-2020-2510)
Oracle JRE CVE-2013-1481 Vulnerability (CVE-2013-1481)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1044)