Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3cp-pq72-hjpv

Опубликовано: 13 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

starcitizentools/citizen-skin allows stored XSS in menu heading message

Summary

All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.

Details

The system messages for menu headings are inserted unescaped into raw HTML: https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/templates/Menu.mustache#L8-L10

PoC

  1. Go to any article using citizen with the uselang parameter set to x-xss
  2. A large number of alerts will be shown for various messages, e.g.: image image

On the main page of my test wiki, the following messages were shown: navigation, notifications, user-interface-preferences, personaltools, variants, views, associated-pages, cactions and toolbox.

Impact

This impacts wikis where a group has the editinterface but not the editsitejs user right.

Пакеты

Наименование

starcitizentools/citizen-skin

composer
Затронутые версииВерсия исправления

>= 2.4.2, < 3.3.1

3.3.1

EPSS

Процентиль: 11%
0.00038
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
nvd
8 месяцев назад

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.

EPSS

Процентиль: 11%
0.00038
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79