Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1. | |
Title | Citizen allows stored XSS in user registration date message | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-12T18:50:49.300Z
Updated: 2025-06-12T19:12:17.575Z
Reserved: 2025-06-06T15:44:21.555Z
Link: CVE-2025-49578

Updated: 2025-06-12T19:11:40.964Z

Status : Awaiting Analysis
Published: 2025-06-12T19:15:20.610
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-49578

No data.