Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
Title | Citizen allows stored XSS in search no result messages | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-12T18:50:55.931Z
Updated: 2025-06-12T19:05:48.122Z
Reserved: 2025-06-06T15:44:21.555Z
Link: CVE-2025-49576

Updated: 2025-06-12T19:04:31.905Z

Status : Awaiting Analysis
Published: 2025-06-12T19:15:20.313
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-49576

No data.