Reflected XSS Vulnerability in MediaWiki's CheckUser Extension
CVE-2025-53478

5.4MEDIUM

What is CVE-2025-53478?

The CheckUser extension for MediaWiki contains a reflected XSS vulnerability within the Special:Investigate interface. This flaw arises from improper escaping of internationalized system messages displayed in the 'IPs and User agents' tab, potentially allowing attackers to inject malicious scripts that could execute within the user’s browser. Users and administrators should upgrade to the latest versions to mitigate this risk.

Affected Version(s)

Mediawiki - CheckUser extension 1.39.x < 1.39.13

Mediawiki - CheckUser extension 1.42.x < 1.42.7

Mediawiki - CheckUser extension 1.43.x < 1.43.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.