Description
An issue was discovered in the ProofreadPage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. XSS can occur via formatNumNoSeparators.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-20985 Vulnerability (CVE-2024-20985)
Apache HTTP Server Other Vulnerability (CVE-2000-1206)
WordPress Plugin Zendesk Chat Cross-Site Request Forgery (1.4.5)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29208)
WordPress Improper Input Validation Vulnerability (CVE-2020-26596)