Description
An issue was discovered in the ProofreadPage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. XSS can occur via formatNumNoSeparators.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-10378 Vulnerability (CVE-2017-10378)
WordPress Plugin WP Users Exporter CSV Injection (1.4.2)
WordPress Plugin Greenshift-animation and page builder blocks Cross-Site Scripting (4.8.8)
Internet Information Services Other Vulnerability (CVE-2000-0413)
WordPress Plugin Easy Accordion-Best Accordion FAQ Cross-Site Scripting (2.0.21)