CNNVD-202510-2450 Information
CNNVD ID
CNNVD-202510-2450
Related CVE
- CNNVD Published: 2025-10-17
Description (Chinese)
Citizen是Star Citizen Wiki团队的一款美观、易用、响应迅速的MediaWiki皮肤。 Citizen 3.3.0版本至3.9.0版本存在跨站脚本漏洞,该漏洞源于stickyHeader.js中copyButtonAttributes函数处理不当,可能导致存储型跨站脚本攻击。
Description (English)
Citizen is a beautiful, easy-to-use and responsive MediaWiki skin of Star Citizen Wiki’s team. Citizen, versions 3.3.0 to 3.9.0, has a cross-site script loophole, which stems from the inappropriate handling of the CopyButtonAttributes function in stickyheader.js, which may result in a storage-type cross-site script attack.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
Star Citizen Wiki
Published
2025-10-17
Last Modified
2026-02-24
References
https://github.com/StarCitizenTools/mediawiki-skins-Citizen/commit/e006923c6dbf113c9a025ca186ecc09fe7b93a15 https://github.com/StarCitizenTools/mediawiki-skins-Citizen/commit/fbb1d4fe9627281567706f3f6fc99a42ce16fdc4 https://github.com/StarCitizenTools/mediawiki-skins-Citizen/security/advisories/GHSA-g955-vw6w-v6pp https://access.redhat.com/security/cve/cve-2025-62508
Share on: