Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-53368

Опубликовано: 03 июл. 2025
Источник: nvd
CVSS3: 8.6
CVSS3: 5.4
EPSS Низкий

Описание

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-site scripting (XSS) payloads into the DOM for other users who are searching for specific pages. This issue has been patched in version 3.4.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:starcitizen.tools:citizen:*:*:*:*:*:mediawiki:*:*
Версия от 1.9.4 (включая) до 3.4.0 (исключая)

EPSS

Процентиль: 8%
0.0003
Низкий

8.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.6
github
7 месяцев назад

starcitizentools/citizen-skin is vulnerable to Stored XSS attack in the legacy search bar through page descriptions

EPSS

Процентиль: 8%
0.0003
Низкий

8.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79