Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Starcitizentools
Starcitizentools mediawiki-skins-citizen |
|
CPEs | cpe:2.3:a:starcitizentools:mediawiki-skins-citizen:2.6.3:*:*:*:*:*:*:* | |
Vendors & Products |
Starcitizentools
Starcitizentools mediawiki-skins-citizen |
|
Metrics |
ssvc
|
Mon, 30 Sep 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0. | |
Title | starcitizentools/citizen-skin vulnerable to stored, self-XSS in the "real name" field | |
Weaknesses | CWE-79 CWE-80 |
|
References |
|
|
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-30T17:09:40.192Z
Updated: 2024-09-30T17:25:48.104Z
Reserved: 2024-09-25T21:46:10.929Z
Link: CVE-2024-47536
Vulnrichment
Updated: 2024-09-30T17:25:41.382Z
NVD
Status : Awaiting Analysis
Published: 2024-09-30T17:15:04.780
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-47536
Redhat
No data.