An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.
This Cyber News was published on www.tenable.com. Publication date: Fri, 12 Jan 2024 10:46:03 +0000