Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18207 | starcitizentools/citizen-skin allows stored XSS in preference menu heading messages |
Github GHSA |
GHSA-jwr7-992g-68mh | starcitizentools/citizen-skin allows stored XSS in preference menu heading messages |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 22 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Starcitizen.tools
Starcitizen.tools citizen |
|
| CPEs | cpe:2.3:a:starcitizen.tools:citizen:*:*:*:*:*:mediawiki:*:* | |
| Vendors & Products |
Starcitizen.tools
Starcitizen.tools citizen |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
| Title | Citizen allows stored XSS in preference menu headings | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-12T19:01:58.426Z
Reserved: 2025-06-06T15:44:21.555Z
Link: CVE-2025-49577
Updated: 2025-06-12T19:00:40.275Z
Status : Analyzed
Published: 2025-06-12T19:15:20.463
Modified: 2025-08-22T18:52:55.133
Link: CVE-2025-49577
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:51:37Z
EUVD
Github GHSA