Description
An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.
Remediation
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1318)
Oracle JRE CVE-2013-2435 Vulnerability (CVE-2013-2435)
WordPress Plugin AzonPost Cross-Site Scripting (1.3)
Joomla! Core 1.5.x Variable Injection (1.5.0 - 1.5.6)
WordPress Plugin WPML (WordPress Multilingual) Multiple Vulnerabilities (3.1.8.6)