The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are inserted into raw HTML without proper escaping. Attackers can exploit this by injecting JavaScript payloads via the uselang=x-xss language override, which causes crafted message keys to be rendered unescaped. This issue affects Mediawiki - ApprovedRevs extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
History

Mon, 07 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
Description The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are inserted into raw HTML without proper escaping. Attackers can exploit this by injecting JavaScript payloads via the uselang=x-xss language override, which causes crafted message keys to be rendered unescaped. This issue affects Mediawiki - ApprovedRevs extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Title ApprovedRevs: Stored Cross-Site Scripting (XSS) via unsanitized system messages
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published: 2025-07-07T15:13:38.574Z

Updated: 2025-07-07T19:16:14.015Z

Reserved: 2025-06-30T15:20:44.462Z

Link: CVE-2025-53487

cve-icon Vulnrichment

Updated: 2025-07-07T19:16:08.320Z

cve-icon NVD

Status : Received

Published: 2025-07-07T16:15:25.623

Modified: 2025-07-07T20:15:27.617

Link: CVE-2025-53487

cve-icon Redhat

No data.