CVE-2025-62653: Stored XSS through system messages in PollNY
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PollNY extension allows Stored XSS.This issue affects MediaWiki PollNY extension: 1.39, 1.43, 1.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62653?
CVE-2025-62653 is categorized as a high severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-62653?
To fix CVE-2025-62653, update the MediaWiki PollNY extension to a version higher than 1.44, as this issue affects versions 1.39 to 1.44.
What type of vulnerability is CVE-2025-62653?
CVE-2025-62653 is an improperly handled input vulnerability that leads to stored cross-site scripting (XSS) in the MediaWiki PollNY extension.
Which versions of the MediaWiki PollNY extension are affected by CVE-2025-62653?
CVE-2025-62653 affects the MediaWiki PollNY extension versions 1.39, 1.43, and 1.44.
What impact does CVE-2025-62653 have on users?
Users vulnerable to CVE-2025-62653 may be exposed to malicious scripts that can steal sensitive data or perform actions on their behalf.