Description
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Remediation
References
Related Vulnerabilities
Atlassian Jira Incorrect Default Permissions Vulnerability (CVE-2019-20106)
WordPress Plugin Lightbox Multiple Unspecified Vulnerabilities (2.0.7)
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-38843)
WordPress Plugin WP125 Multiple Cross-Site Scripting Vulnerabilities (1.4.4)
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4466)