MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-37255 - Vulnerability Database

MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-37255

Medium
Reference: CVE-2023-37255
Title: MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser a check of the quotget editsquot type is vulnerable to HTML injection through the User-Agent HTTP request header.