Description
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin PHP Analytics Arbitrary File Upload (1.0.0.2)
WordPress Plugin MailPoet Newsletters (Previous) Arbitrary File Upload (2.6.7)
Oracle JRE CVE-2012-0507 Vulnerability (CVE-2012-0507)
Squid Improper Privilege Management Vulnerability (CVE-2019-12522)
WordPress Plugin Portfolio Responsive Gallery SQL Injection (1.1.7)