Логотип exploitDog
bind:CVE-2025-53368
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-53368

Количество 2

Количество 2

nvd логотип

CVE-2025-53368

7 месяцев назад

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-site scripting (XSS) payloads into the DOM for other users who are searching for specific pages. This issue has been patched in version 3.4.0.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-rq6g-6g94-jfr4

7 месяцев назад

starcitizentools/citizen-skin is vulnerable to Stored XSS attack in the legacy search bar through page descriptions

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-53368

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-site scripting (XSS) payloads into the DOM for other users who are searching for specific pages. This issue has been patched in version 3.4.0.

CVSS3: 8.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-rq6g-6g94-jfr4

starcitizentools/citizen-skin is vulnerable to Stored XSS attack in the legacy search bar through page descriptions

CVSS3: 8.6
0%
Низкий
7 месяцев назад

Уязвимостей на страницу