{"id":"GHSA-p85q-mww9-gwqf","summary":"Citizen Short Description stored XSS vulnerability through wikitext","details":"### Summary\nShort descriptions are not properly sanitized by the ShortDescription before being inserted as HTML using `mw.util.addSubtitle`, allowing any user to insert arbitrary HTML into the DOM by editing a page.\n\n### Details\nThe description provided by the user via the `{{SHORTDESC:}}` parser function is insufficiently sanitized by the `sanitize()` function, as html entities are decoded:\nhttps://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/blob/7244b1e8b5cb6dbd7e546c5be7fed8a56e33d065/includes/Hooks/ParserHooks.php#L147-L159\nVia JS, the short description is then passed to `mw.util.addSubtitle`, which inserts it as raw HTML:\nhttps://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/blob/7244b1e8b5cb6dbd7e546c5be7fed8a56e33d065/modules/ext.shortDescription.js#L8\nhttps://github.com/wikimedia/mediawiki/blob/96372101b3c579d9992e8a31a3ccd90a937cac47/resources/src/mediawiki.util/util.js#L552-L563\n\n### PoC\n1. Enable ShortDescription\n2. Make sure `$wgShortDescriptionEnableTagline` is set to `true` (this is the default)\n3. Create a page and insert the following wikitext: `{{SHORTDESC:&lt;img src=\"\" onerror=\"alert('shortdescription xss')\"&gt;}}`\n4. Visit the page\n\n![image](https://github.com/user-attachments/assets/8e467f28-3bb5-4462-b28b-14e145be743f)\n![image](https://github.com/user-attachments/assets/39e132c3-6a92-4f24-8aef-b915e8560f63)\n\n\n### Impact\nArbitrary HTML can be inserted into the DOM by any user, allowing for JavaScript to be executed.","aliases":["CVE-2025-53369"],"modified":"2025-07-03T22:27:19.935348Z","published":"2025-07-03T21:38:37Z","database_specific":{"github_reviewed_at":"2025-07-03T21:38:37Z","nvd_published_at":"2025-07-03T20:15:23Z","cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/security/advisories/GHSA-p85q-mww9-gwqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53369"},{"type":"WEB","url":"https://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/commit/bc4fdbaeb1dff127fb6d08c0d385b64aa128c8f8"},{"type":"PACKAGE","url":"https://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription"}],"affected":[{"package":{"name":"starcitizentools/short-description","ecosystem":"Packagist","purl":"pkg:composer/starcitizentools/short-description"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-p85q-mww9-gwqf/GHSA-p85q-mww9-gwqf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"}]}