Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.
Remediation
References
Related Vulnerabilities
WordPress Plugin 1player Cross-Site Scripting (1.3)
WordPress Plugin Polylang Cross-Site Scripting (1.5.1)
WordPress Plugin Kindeditor For WordPress Cross-Site Scripting (1.3.3)
Internet Information Services Other Vulnerability (CVE-1999-0737)
WordPress Plugin YaySMTP-Simple WP SMTP Mail Cross-Site Scripting (2.4.5)