Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 4.0.1.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19899 | Citizen Short Description stored XSS vulnerability through wikitext |
Github GHSA |
GHSA-p85q-mww9-gwqf | Citizen Short Description stored XSS vulnerability through wikitext |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 4.0.1. | |
| Title | Citizen Short Description stored XSS vulnerability through wikitext | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-03T20:11:01.943Z
Reserved: 2025-06-27T12:57:16.121Z
Link: CVE-2025-53369
Updated: 2025-07-03T20:10:51.760Z
Status : Awaiting Analysis
Published: 2025-07-03T20:15:23.737
Modified: 2025-07-08T16:19:11.700
Link: CVE-2025-53369
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA