Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 4.0.1.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 4.0.1. | |
Title | Citizen Short Description stored XSS vulnerability through wikitext | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-03T19:57:55.147Z
Updated: 2025-07-03T20:11:01.943Z
Reserved: 2025-06-27T12:57:16.121Z
Link: CVE-2025-53369

Updated: 2025-07-03T20:10:51.760Z

Status : Received
Published: 2025-07-03T20:15:23.737
Modified: 2025-07-03T20:15:23.737
Link: CVE-2025-53369

No data.