Reflected XSS Vulnerability in MediaWiki CheckUser Extension
CVE-2025-53480

5.4MEDIUM

What is CVE-2025-53480?

The CheckUser extension in MediaWiki features a vulnerability within the Account information tab on the Special:Investigate page. This flaw arises due to certain internationalized messages being rendered without adequate escaping, enabling attackers to exploit this by appending certain parameters to the URL. Such exploitation can lead to reflected XSS, allowing malicious scripts to execute in the context of another user's session when the affected message keys are rendered in the user interface.

Affected Version(s)

Mediawiki - CheckUser extension 1.39.x < 1.39.13

Mediawiki - CheckUser extension 1.42.x < 1.42.7

Mediawiki - CheckUser extension 1.43.x < 1.43.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.