CVE-2022-34911 | MediaWiki up to 1.35.6/1.37.2/1.38.0 Welcome successfulAction Username escape output (EUVD-2022-37815)
A vulnerability classified as critical was found in MediaWiki up to 1.35.6/1.37.2/1.38.0. This impacts the function SpecialCreateAccount::successfulAction of the component Welcome Handler. Such manipulation of the argument Username leads to escaping of output.
This vulnerability is listed as CVE-2022-34911. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.