Medium severity6.5NVD Advisory· Published Jun 3, 2024· Updated Jun 17, 2026
CVE-2024-36123
CVE-2024-36123
Description
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page MediaWiki:Tagline has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the editinterface permission, or sysops). This vulnerability is fixed in 2.16.0.
Affected products
3- Range: < 2.16.0
Patches
Vulnerability mechanics
References
5- github.com/StarCitizenTools/mediawiki-skins-Citizen/commit/4a43280242f33e54643087da4a7f40970d2640c9nvdPatch
- github.com/StarCitizenTools/mediawiki-skins-Citizen/security/advisories/GHSA-jhm6-qjhq-5mf9nvdExploitVendor Advisory
- github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/c11fbf67a99366d5a40ef880469b222679e3b475/includes/Components/CitizenComponentPageHeading.phpnvdProduct
- github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/c11fbf67a99366d5a40ef880469b222679e3b475/includes/Components/CitizenComponentPageHeading.phpnvdProduct
- github.com/StarCitizenTools/mediawiki-skins-Citizen/releasesnvdRelease Notes
News mentions
0No linked articles in our index yet.