CVE-2025-62702: Stored XSS through system messages
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - PageTriage Extension allows Stored XSS.This issue affects Mediawiki - PageTriage Extension: from master before 1.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62702?
The severity of CVE-2025-62702 is categorized as high due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-62702?
To fix CVE-2025-62702, upgrade the Mediawiki PageTriage Extension to version 1.44 or later.
What systems are affected by CVE-2025-62702?
CVE-2025-62702 affects the Mediawiki PageTriage Extension version from master before 1.44.
What type of vulnerability is CVE-2025-62702?
CVE-2025-62702 is an improper neutralization of input that leads to cross-site scripting (XSS) vulnerabilities.
Can CVE-2025-62702 lead to data breaches?
Yes, CVE-2025-62702 can lead to data breaches if an attacker exploits the stored XSS vulnerability.