Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1. | |
Title | Citizen allows stored XSS in menu heading message | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-12T18:50:44.360Z
Updated: 2025-06-12T19:16:43.720Z
Reserved: 2025-06-06T15:44:21.555Z
Link: CVE-2025-49579

Updated: 2025-06-12T19:16:35.410Z

Status : Awaiting Analysis
Published: 2025-06-12T19:15:20.750
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-49579

No data.