XSS Vulnerability in Wikimedia Foundation CheckUser Product
CVE-2025-61648
NONE
What is CVE-2025-61648?
The vulnerability in Wikimedia Foundation's CheckUser product involves improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts. This exploitation can lead to unauthorized actions or data theft when affected users view manipulated web content. It primarily impacts versions prior to 1.44.1, specifically in the modules related to temporary accounts, further underscoring the importance of robust input validation mechanisms in web applications.
Affected Version(s)
CheckUser * < 1.44.1
