Description
An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.
References
phabricator.wikimedia.org/T340221
lists.fedoraproject.org/...FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/ (FEDORA-2024-2c564b942d)
phabricator.wikimedia.org/T340221
lists.fedoraproject.org/...FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/ (FEDORA-2024-2c564b942d)