CVE Database
/

CVE-2024-47536

Back to search

CVE-2024-47536

Published: Sep 30, 2024

Modified: Sep 30, 2024

PUBLISHED

Description

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.

VendorProductVersions

StarCitizenTools

mediawiki-skins-Citizen

affected
>= 2.6.3, < 2.31.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now