We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53478

CheckUser: Reflected Cross-Site Scripting (XSS) in Special:Investigate via unsanitized i18n messages



Description

The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects Mediawiki - CheckUser extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

Reserved 2025-06-30 | Published 2025-07-07 | Updated 2025-07-07 | Assigner wikimedia-foundation

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

1.39.x before 1.39.13
affected

1.42.x before 1.42.7
affected

1.43.x before 1.43.2
affected

References

phabricator.wikimedia.org/T394692

gerrit.wikimedia.org/...21b6800ff4d813a33ee9fe9b7ccf070b6b2e

cve.org (CVE-2025-53478)

nvd.nist.gov (CVE-2025-53478)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53478

Support options

Helpdesk Chat, Email, Knowledgebase