PT-2024-32649 · Mediawiki · Mediawiki Citizen Skin

Blankeclair

·

Published

2024-09-30

·

Updated

2025-08-25

·

CVE-2024-47536

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki Citizen Skin versions prior to 2.31.0
Description The issue allows a user with the editmyprivateinfo right or who can otherwise change their name to perform a self-XSS attack by setting their "real name" to an XSS payload. This can be done by modifying the "real name" field in the user's preferences to include malicious script code, such as <script>alert("Admin with a propensity for self-XSSes")</script>. The vulnerability is triggered when the user saves their settings and the Citizen skin is used.
Recommendations For versions prior to 2.31.0, update to version 2.31.0 or later to fix the vulnerability. As a temporary workaround, consider restricting the ability for users to change their names or limiting access to the "real name" field in the user preferences to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47536
GHSA-62R2-GCXR-426X

Affected Products

Mediawiki Citizen Skin