Description
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Remediation
References
Related Vulnerabilities
Moodle Configuration Vulnerability (CVE-2012-0797)
WordPress Plugin WooCommerce PDF Invoice Bulk Download Cross-Site Scripting (1.0.0)
Apache HTTP Server CVE-2013-5704 Vulnerability (CVE-2013-5704)
Apache HTTP Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-1927)
WordPress Plugin Moova for WooCommerce Cross-Site Scripting (3.5)