Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
Remediation
References
Related Vulnerabilities
Python Integer Overflow or Wraparound Vulnerability (CVE-2008-1679)
WordPress Plugin Donations Privilege Escalation (1.3)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-1580)
phpBB Improper Input Validation Vulnerability (CVE-2019-9826)
OpenSSL Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-0778)