PT-2025-28243 · Mediawiki · Mediawiki

John Doe

+1

·

Published

2025-07-07

·

Updated

2025-07-07

·

CVE-2025-53478

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mediawiki - CheckUser extension versions 1.39.0 through 1.39.12 Mediawiki - CheckUser extension versions 1.42.0 through 1.42.6 Mediawiki - CheckUser extension versions 1.43.0 through 1.43.1
Description: The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab.
Recommendations: For versions 1.39.0 through 1.39.12, update to version 1.39.13 or later. For versions 1.42.0 through 1.42.6, update to version 1.42.7 or later. For versions 1.43.0 through 1.43.1, update to version 1.43.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-53478

Affected Products

Mediawiki