Description
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the `editinterface` permission, or sysops). This vulnerability is fixed in 2.16.0.
References
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
6.5 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2024-06-03T13:15:08.843Z
1 year agoLast modified
2025-08-22T13:58:19.607Z
7 months ago