An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
{
"cpes": [
"cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*",
"cpe:2.3:a:mediawiki:mediawiki:1.37.0:-:*:*:*:*:*:*",
"cpe:2.3:a:mediawiki:mediawiki:1.37.0:rc0:*:*:*:*:*:*",
"cpe:2.3:a:mediawiki:mediawiki:1.37.0:rc1:*:*:*:*:*:*",
"cpe:2.3:a:mediawiki:mediawiki:1.37.0:rc2:*:*:*:*:*:*"
],
"severity": "Medium"
}