PT-2025-27831 · Unknown+1 · Shortdescription Extension+1
Somemwdev
·
Published
2025-07-03
·
Updated
2025-07-03
·
CVE-2025-53370
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Citizen MediaWiki skin versions 1.9.4 through 3.4.0
Description:
The Citizen MediaWiki skin has an issue where short descriptions set via the ShortDescription extension are inserted as raw HTML, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 3.4.0.
Recommendations:
For versions 1.9.4 through 3.4.0, update to version 3.4.0 to patch this issue. As a temporary workaround, consider restricting the use of the ShortDescription extension until the update is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mediawiki Citizen Skin
Shortdescription Extension