CVE-2025-53369 Information

Description

Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0 short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been patched in version 4.0.1.

Reference

https://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/commit/bc4fdbaeb1dff127fb6d08c0d385b64aa128c8f8 https://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/security/advisories/GHSA-p85q-mww9-gwqf

CNNVD-202507-323 (Published: 2025-07-03)

Share on: