Description
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced WP Columns Cross-Site Scripting (2.0.6)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2020-5360)
WordPress Plugin Great Quotes Cross-Site Scripting (1.0.0)
Joomla! Core 1.5.x Information Disclosure (1.5.0 - 1.5.23)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-25763)