Description
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
Remediation
References
Related Vulnerabilities
WordPress Plugin Amministrazione Trasparente Cross-Site Request Forgery (7.1)
MySQL CVE-2017-3642 Vulnerability (CVE-2017-3642)
MySQL Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-6664)
MySQL CVE-2019-2795 Vulnerability (CVE-2019-2795)
Joomla Improper Input Validation Vulnerability (CVE-2006-4468)