Arbitrary HTML Insertion Vulnerability in MediaWiki Skin by StarCitizenTools
CVE-2025-53370

8.6HIGH

Key Information:

Vendor
CVE Published:
3 July 2025

What is CVE-2025-53370?

The Citizen MediaWiki skin, spanning versions 1.9.4 to prior to 3.4.0, harbors a security flaw where short descriptions from the ShortDescription extension are directly inserted into the DOM as raw HTML. This allows users to manipulate page content by injecting arbitrary HTML, potentially leading to various attacks such as cross-site scripting (XSS). Users are strongly encouraged to update to version 3.4.0 or later, where this vulnerability has been addressed and patched.

Affected Version(s)

mediawiki-skins-Citizen >= 65a7ffd927467c8c3557146d1ac6de62b0369b6c, < c85a40bddc8651fff66df83a72debddcb34f0521 < 65a7ffd927467c8c3557146d1ac6de62b0369b6c, c85a40bddc8651fff66df83a72debddcb34f0521

mediawiki-skins-Citizen >= 1.9.4, < 3.4.0 < 1.9.4, 3.4.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53370 : Arbitrary HTML Insertion Vulnerability in MediaWiki Skin by StarCitizenTools