CVE-2025-61650: UserInfoCard is vulnerable to message key stored XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Services/CheckUserUserInfoCardService.Php.
This issue affects CheckUser: from before 795bf333272206a0189050d975e94b70eb7dc507.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61650?
The severity of CVE-2025-61650 is classified as medium due to its potential for exploitation through stored XSS attacks.
How do I fix CVE-2025-61650?
To fix CVE-2025-61650, sanitize and validate all inputs in the CheckUserUserInfoCardService.php file to prevent XSS vulnerabilities.
What software is affected by CVE-2025-61650?
CVE-2025-61650 affects the Wikimedia Foundation's CheckUser software version prior to the fix implemented after commit 795bf333272206a0189050d975e94b70eb7dc507.
What kind of attack can be executed through CVE-2025-61650?
CVE-2025-61650 allows attackers to execute stored XSS attacks by injecting malicious scripts into user input fields.
Is there a known exploit for CVE-2025-61650?
As of the latest information available, there is no publicly known exploit specifically targeting CVE-2025-61650.