Arbitrary HTML Insertion Vulnerability in MediaWiki Skin by StarCitizenTools
CVE-2025-53370
8.6HIGH
What is CVE-2025-53370?
The Citizen MediaWiki skin, spanning versions 1.9.4 to prior to 3.4.0, harbors a security flaw where short descriptions from the ShortDescription extension are directly inserted into the DOM as raw HTML. This allows users to manipulate page content by injecting arbitrary HTML, potentially leading to various attacks such as cross-site scripting (XSS). Users are strongly encouraged to update to version 3.4.0 or later, where this vulnerability has been addressed and patched.
Affected Version(s)
mediawiki-skins-Citizen >= 65a7ffd927467c8c3557146d1ac6de62b0369b6c, < c85a40bddc8651fff66df83a72debddcb34f0521 < 65a7ffd927467c8c3557146d1ac6de62b0369b6c, c85a40bddc8651fff66df83a72debddcb34f0521
mediawiki-skins-Citizen >= 1.9.4, < 3.4.0 < 1.9.4, 3.4.0