PT-2025-27830 · Mediawiki · Mediawiki Citizen Skin
Somemwdev
·
Published
2025-07-03
·
Updated
2025-07-03
·
CVE-2025-53368
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Citizen MediaWiki skin versions 1.9.4 through 3.4.0
Description:
The Citizen MediaWiki skin has an issue where page descriptions are inserted into raw HTML without proper sanitization when using the old search bar. This allows any user with page editing privileges to insert cross-site scripting (XSS) payloads into the DOM for other users who are searching for specific pages.
Recommendations:
For versions 1.9.4 through 3.4.0, update to version 3.4.0 to resolve the issue.
As a temporary workaround, consider disabling the old search bar until a patch is available.
Restrict access to page editing privileges to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mediawiki Citizen Skin