Description
An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.
Remediation
References
Related Vulnerabilities
WordPress Plugin WPJobBoard Cross-Site Scripting (5.5.3)
WordPress Plugin Royal Gallery 'upload.php' Arbitrary File Upload (2.1)
WordPress Plugin Digital Climate Strike WP Malicious Redirects (1.0.0)
Joomla! Core 3.9.x CSV Injection (3.9.0 - 3.9.6)
WordPress Plugin WP-Members Membership Cross-Site Scripting (3.1.7)