CVE-2025-61648: Stored XSS through system messages in CheckUser
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/ShowIPButton.Vue, modules/ext.CheckUser.TempAccounts/SpecialBlock.Js.
This issue affects CheckUser: from before 1.44.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61648?
CVE-2025-61648 is classified as a critical severity vulnerability due to its potential for exploiting stored XSS in user messages.
How do I fix CVE-2025-61648?
To fix CVE-2025-61648, update to the latest version of the Wikimedia Foundation CheckUser software, ensuring you are beyond version 1.44.1.
What impact does CVE-2025-61648 have on users?
CVE-2025-61648 can allow attackers to execute malicious scripts in the context of other users, potentially leading to data theft or session hijacking.
Is CVE-2025-61648 being actively exploited?
As of the current information, there are indications that CVE-2025-61648 is being actively targeted by attackers.
What component of Wikimedia Foundation CheckUser is affected by CVE-2025-61648?
CVE-2025-61648 specifically affects the ShowIPButton component within the CheckUser extension.