CVE-2025-62663: Stored XSS through a system message in UploadWizard
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - UploadWizard Extension allows Stored XSS.This issue affects Mediawiki - UploadWizard Extension: from master before 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62663?
CVE-2025-62663 has a high severity due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-62663?
To fix CVE-2025-62663, update the Mediawiki - UploadWizard Extension to version 1.39 or later.
What is the impact of CVE-2025-62663 on my system?
CVE-2025-62663 can allow an attacker to execute malicious scripts in the context of a user's session through Stored XSS.
Which versions of Mediawiki - UploadWizard Extension are affected by CVE-2025-62663?
CVE-2025-62663 affects all versions of Mediawiki - UploadWizard Extension prior to 1.39.
Is user data at risk due to CVE-2025-62663?
Yes, due to the Stored XSS vulnerability in CVE-2025-62663, user data could be compromised if exploited by an attacker.