CVE-2025-62667: Stored XSS through article extracts in GrowthExperiments
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Stored XSS.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62667?
CVE-2025-62667 is classified as a stored cross-site scripting (XSS) vulnerability in the Mediawiki - GrowthExperiments Extension.
How do I fix CVE-2025-62667?
To fix CVE-2025-62667, upgrade the Mediawiki - GrowthExperiments Extension to version 1.39 or later.
Which versions of Mediawiki - GrowthExperiments Extension are affected by CVE-2025-62667?
CVE-2025-62667 affects all versions of the Mediawiki - GrowthExperiments Extension prior to 1.39.
Can CVE-2025-62667 be exploited remotely?
Yes, CVE-2025-62667 can be exploited remotely if an attacker can inject malicious scripts into the web pages served by the affected extension.
What are the potential impacts of exploiting CVE-2025-62667?
Exploiting CVE-2025-62667 could lead to unauthorized access to user sessions, data theft, or defacement of the affected website.