CVE-2025-49579

MEDIUM

Citizen < 3.3.1 - XSS

Title source: rule
STIX 2.1

Description

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
starcitizen.tools/citizen < 3.3.1
starcitizentools/citizen-skin 2.4.2 - 3.3.1Packagist
Published Jun 12, 2025
Tracked Since Feb 18, 2026