MediaWiki just released a security update. If you haven't changed the defaults to support Ajax, you are fine, but if you have - either upgrade or change $wgUseAjax to off in LocalSettings.php The Release Notes are here