Mediawiki · Msupload Extension · CVE-2025-7362
Name of the Vulnerable Software and Affected Versions:
MediaWiki - MsUpload extension versions 1.39.X through 1.39.12
MediaWiki - MsUpload extension versions 1.42.X through 1.42.6
MediaWiki - MsUpload extension versions 1.43.X through 1.43.1
Description:
The MsUpload extension for MediaWiki is vulnerable to stored XSS via the `msu-continue` system message, which is inserted into the DOM without proper sanitization. This issue occurs in the file upload UI when the same filename is uploaded twice.
Recommendations:
For MediaWiki - MsUpload extension versions 1.39.X through 1.39.12, update to version 1.39.13 or later.
For MediaWiki - MsUpload extension versions 1.42.X through 1.42.6, update to version 1.42.7 or later.
For MediaWiki - MsUpload extension versions 1.43.X through 1.43.1, update to version 1.43.2 or later.