Vulnerability Description
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the `editinterface` permission, or sysops). This vulnerability is fixed in 2.16.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Starcitizen.Tools | Citizen | < 2.16.0 |
Related Weaknesses (CWE)
References
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/c11fbf67a99366dProduct
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/c11fbf67a99366dProduct
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/commit/4a43280242f33Patch
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/releasesRelease Notes
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/security/advisories/ExploitVendor Advisory
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/c11fbf67a99366dProduct
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/c11fbf67a99366dProduct
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/commit/4a43280242f33Patch
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/releasesRelease Notes
- https://github.com/StarCitizenTools/mediawiki-skins-Citizen/security/advisories/ExploitVendor Advisory
FAQ
What is CVE-2024-36123?
CVE-2024-36123 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected b...
How severe is CVE-2024-36123?
CVE-2024-36123 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36123?
Check the references section above for vendor advisories and patch information. Affected products include: Starcitizen.Tools Citizen.