mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
1.0 KiB
1.0 KiB
CVE-2024-36123
Description
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page MediaWiki:Tagline
has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the editinterface
permission, or sysops). This vulnerability is fixed in 2.16.0.
POC
Reference
Github
No PoCs found on GitHub currently.