An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definitions. e.g., in SpecialCheckUserLog.
This Cyber News was published on www.tenable.com. Publication date: Fri, 12 Jan 2024 10:46:03 +0000