Citizen是Star Citizen Wiki团队的一款美观、易用、响应迅速的MediaWiki皮肤。 Citizen 3.3.1之前版本存在跨站脚本漏洞,该漏洞源于Menu.mustache模板中的菜单标题插入原始HTML,可能导致任意HTML注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| StarCitizenTools | mediawiki-skins-Citizen | >= 54c8717d45ce1594918f11cb9ce5d0ccd8dfee65, < 93c36ac778397e0e7c46cf7adb1e5d848265f1bd | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-49575 | 6.5 MEDIUM | Citizen allows stored XSS in Command Palette tip messages |
| CVE-2025-49577 | 6.5 MEDIUM | Citizen allows stored XSS in preference menu headings |
| CVE-2025-49578 | 6.5 MEDIUM | Citizen allows stored XSS in user registration date message |
| CVE-2025-49576 | 6.5 MEDIUM | Citizen allows stored XSS in search no result messages |
No comments yet