{"id":"GHSA-jwr7-992g-68mh","summary":"starcitizentools/citizen-skin allows stored XSS in preference menu heading messages","details":"### Summary\nVarious preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.\n\n### Details\nThe `innerHtml` of the label div is set to the `textContent` of the label, essentially unsanitizing the system messages:\nhttps://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/407052e7069bdeae927d6f1a2a1c9a45b473bf9a/resources/skins.citizen.preferences/addPortlet.polyfill.js#L18\n\n\n### PoC\n1. Edit `citizen-feature-custom-font-size-name` (or any other message displayed in a heading in the preferences menu) to `\u003cimg src=\"\" onerror=\"alert('citizen-feature-custom-font-size-name')\"\u003e` (script tags don't work here due to the way the HTML is inserted)\n2. Open the preferences menu\n![image](https://github.com/user-attachments/assets/b75f100d-09cc-443c-b635-e9d6ab48d133)","aliases":["CVE-2025-49577"],"modified":"2025-06-13T14:29:35.649553Z","published":"2025-06-13T14:08:12Z","database_specific":{"nvd_published_at":"2025-06-12T19:15:20Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-06-13T14:08:12Z"},"references":[{"type":"WEB","url":"https://github.com/StarCitizenTools/mediawiki-skins-Citizen/security/advisories/GHSA-jwr7-992g-68mh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49577"},{"type":"WEB","url":"https://github.com/StarCitizenTools/mediawiki-skins-Citizen/commit/93c36ac778397e0e7c46cf7adb1e5d848265f1bd"},{"type":"WEB","url":"https://github.com/StarCitizenTools/mediawiki-skins-Citizen/commit/a741639085d70c22a9f49890542a142a223bf981"},{"type":"PACKAGE","url":"https://github.com/StarCitizenTools/mediawiki-skins-Citizen"}],"affected":[{"package":{"name":"starcitizentools/citizen-skin","ecosystem":"Packagist","purl":"pkg:composer/starcitizentools/citizen-skin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.13.0"},{"fixed":"3.3.1"}]}],"versions":["v2.13.0","v2.13.1","v2.13.2","v2.13.3","v2.13.4","v2.13.5","v2.14.0","v2.14.1","v2.15.0","v2.15.1","v2.16.0","v2.16.1","v2.17.0","v2.17.1","v2.17.2","v2.18.0","v2.18.1","v2.19.0","v2.20.0","v2.21.0","v2.22.0","v2.22.1","v2.23.0","v2.24.0","v2.25.0","v2.26.0","v2.27.0","v2.28.0","v2.29.0","v2.30.0","v2.31.0","v2.32.0","v2.33.0","v2.34.0","v2.35.0","v2.36.0","v2.37.0","v2.38.0","v2.38.1","v2.38.2","v2.38.3","v2.39.0","v2.39.1","v2.39.2","v2.39.3","v2.39.4","v2.40.0","v2.40.1","v2.40.2","v3.0.0","v3.1.0","v3.2.0","v3.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-jwr7-992g-68mh/GHSA-jwr7-992g-68mh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"}]}