Cross-site scripting (XSS) vulnerability in the Hovercards extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors related to text extracts.Referenceshttp://www.openwall.com/lists/oss-security/2015/01/03/13http://www.openwall.com/lists/oss-security/2014/12/21/2https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-December/000173.htmlhttps://phabricator.wikimedia.org/T69180