Related Vulnerabilities: CVE-2021-41798  

A cross-site scripting vulnerability in Special:Search has been found in MediaWiki before version 1.36.2.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

A cross-site scripting vulnerability in Special:Search has been found in MediaWiki before version 1.36.2.

AVG-2434 mediawiki 1.36.1-1 Medium Vulnerable

https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/2IFS5CM2YV4VMSODPX3J2LFHKSEWVFV5/
https://phabricator.wikimedia.org/T285515
https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/864635b5debb80d5ac00a8b647eb547a829ea0f8%5E%21/