MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-4307
Multiple cross-site scripting (XSS) vulnerabilities in repo/includes/EntityView.php in the Wikibase extension for MediaWiki 1.19.x before 1.19.8 1.20.x before 1.20.7 and 1.21.x before 1.21.2 allow (1) remote attackers to inject arbitrary web script or HTML via a label in the quotIn other languagesquot section or (2) remote administrators to inject arbitrary web script or HTML via a description.
