Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.
Metrics
Affected Vendors & Products
References
History
Mon, 25 Aug 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Starcitizen.tools
Starcitizen.tools citizen |
|
CPEs | cpe:2.3:a:starcitizen.tools:citizen:*:*:*:*:*:mediawiki:*:* | |
Vendors & Products |
Starcitizen.tools
Starcitizen.tools citizen |
|
Metrics |
cvssV3_1
|
Mon, 30 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Starcitizentools
Starcitizentools mediawiki-skins-citizen |
|
CPEs | cpe:2.3:a:starcitizentools:mediawiki-skins-citizen:2.6.3:*:*:*:*:*:*:* | |
Vendors & Products |
Starcitizentools
Starcitizentools mediawiki-skins-citizen |
|
Metrics |
ssvc
|
Mon, 30 Sep 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0. | |
Title | starcitizentools/citizen-skin vulnerable to stored, self-XSS in the "real name" field | |
Weaknesses | CWE-79 CWE-80 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-30T17:09:40.192Z
Updated: 2024-09-30T17:25:48.104Z
Reserved: 2024-09-25T21:46:10.929Z
Link: CVE-2024-47536

Updated: 2024-09-30T17:25:41.382Z

Status : Analyzed
Published: 2024-09-30T17:15:04.780
Modified: 2025-08-25T02:04:28.420
Link: CVE-2024-47536

No data.