Description
An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.
Remediation
References
Related Vulnerabilities
WordPress Plugin LOGIN AND REGISTRATION ATTEMPTS LIMIT Cross-Site Request Forgery (2.1)
WordPress Plugin JS MultiHotel Multiple Vulnerabilities (2.2.1)
WordPress Plugin Twenty20 Image Before-After Malicious Code (1.6.3)
Joomla CVE-2014-7229 Vulnerability (CVE-2014-7229)
WordPress Plugin Asgaros Forum Multiple Vulnerabilities (1.15.14)