CVE-2025-25287: Lakeus vulnerable to stored XSS via system messages
Lakeus is a simple skin made for MediaWiki. Starting in version 1.0.8 and prior to versions 1.3.1+REL1.39, 1.3.1+REL1.42, and 1.4.0, Lakeus is vulnerable to store cross-site scripting via malicious system messages, though editing the messages requires high privileges. Those with (editinterface) rights can edit system messages that are improperly handled in order to send raw HTML. In the case of lakeus-footermessage, this will affect all users if the server is configured to link back to this repository. Otherwise, the system messages in themeDesigner.js are only used when the user enables it in their preferences. Versions 1.3.1+REL1.39, 1.3.1+REL1.42, and 1.4.0 contain a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
lakeus-footermessageto a version that resolves this vulnerability.Fixed in 1.3.1+REL1.39 - Upgrade
Upgrade
lakeus-footermessageto a version that resolves this vulnerability.Fixed in 1.3.1+REL1.42 - Upgrade
Upgrade
lakeus-footermessageto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25287?
CVE-2025-25287 is classified as a moderate severity vulnerability due to its potential impact on user data through cross-site scripting.
How do I fix CVE-2025-25287?
To fix CVE-2025-25287, upgrade to MediaWiki Lakeus version 1.3.1+REL1.39, 1.3.1+REL1.42, or 1.4.0.
Who is affected by CVE-2025-25287?
CVE-2025-25287 affects users of MediaWiki Lakeus versions 1.8.0 through 1.3.1+REL1.39 and 1.3.1+REL1.42.
What type of attack does CVE-2025-25287 exploit?
CVE-2025-25287 exploits a cross-site scripting vulnerability that can be triggered through malicious system messages.
What are the prerequisites for exploiting CVE-2025-25287?
Exploitation of CVE-2025-25287 requires high privileges to edit system messages on the MediaWiki platform.