Description
An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Dropshix Security Bypass (4.0.13)
WordPress Plugin Nmedia WordPress Member Conversation 'doupload.php' Arbitrary File Upload (1.3)
WordPress Plugin underConstruction Cross-Site Scripting (1.18)
PostgreSQL Other Vulnerability (CVE-2005-1409)
Collabtive Improper Privilege Management Vulnerability (CVE-2013-5027)