PT-2025-25348 · Citizen+1 · Citizen+1

Somemwdev

·

Published

2025-06-12

·

Updated

2025-08-22

·

CVE-2025-49579

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Citizen versions prior to 3.3.1
Description The issue affects the Citizen MediaWiki skin, where system messages in menu headings using the Menu.mustache template are inserted as raw HTML. This allows users with the editinterface right to insert arbitrary HTML into the DOM, potentially impacting wikis. The estimated number of affected devices and real-world incidents are not specified.
Recommendations For versions prior to 3.3.1, update to version 3.3.1 to resolve the issue. As a temporary workaround, consider restricting the editinterface user right to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-49579
GHSA-G3CP-PQ72-HJPV

Affected Products

Citizen
Mediawiki