Security Advisory
CVE-2022-29969
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).