CVE-2025-62671: Stored XSS through wikitext in Cargo
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension befor 3.8.3.
Other sources
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: master.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62671?
CVE-2025-62671 is classified as a medium severity vulnerability due to the potential for stored XSS attacks.
How do I fix CVE-2025-62671?
To fix CVE-2025-62671, update the Mediawiki - Cargo Extension to the latest version where the vulnerability is patched.
What type of vulnerability is CVE-2025-62671?
CVE-2025-62671 is an improper neutralization of input vulnerability, specifically a Stored Cross-site Scripting (XSS) issue.
Which software is affected by CVE-2025-62671?
CVE-2025-62671 affects the Mediawiki - Cargo Extension developed by the Wikimedia Foundation.
What could an attacker achieve with CVE-2025-62671?
An attacker exploiting CVE-2025-62671 could potentially execute malicious scripts in the context of an affected user, leading to session hijacking or data theft.