MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-45474 - Vulnerability Database

MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-45474

Medium
Reference: CVE-2021-45474
Title: MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

In MediaWiki through 1.37 the Special:ImportFile URI (aka FileImporter) allows XSS as demonstrated by the clientUrl parameter.