Description
An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.
Remediation
References
Related Vulnerabilities
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.6)
MediaWiki Missing Authorization Vulnerability (CVE-2019-12469)
OpenSSL Out-of-bounds Read Vulnerability (CVE-2004-0112)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.36)
Envoy Proxy Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-15225)