Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Starcitizen.tools
Starcitizen.tools citizen |
|
CPEs | cpe:2.3:a:starcitizen.tools:citizen:*:*:*:*:*:mediawiki:*:* | |
Vendors & Products |
Starcitizen.tools
Starcitizen.tools citizen |
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1. | |
Title | Citizen allows stored XSS in menu heading message | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-12T19:16:43.720Z
Reserved: 2025-06-06T15:44:21.555Z
Link: CVE-2025-49579

Updated: 2025-06-12T19:16:35.410Z

Status : Analyzed
Published: 2025-06-12T19:15:20.750
Modified: 2025-08-22T18:44:01.730
Link: CVE-2025-49579

No data.

Updated: 2025-07-13T21:48:33Z