CVE-2024-47536
30.09.2024, 17:15
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.
| Vendor | Product | Version |
|---|---|---|
| starcitizen.tools | citizen | 𝑥 < 2.31.0 |
𝑥
= Vulnerable software versions
References