CVE-2025-67477: Stored XSS through a system message in Special:ApiSandbox
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js.
This issue affects MediaWiki: from before 1.44.3, 1.45.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67477?
CVE-2025-67477 is classified as a high-severity vulnerability due to the potential for stored XSS attacks.
How do I fix CVE-2025-67477?
To fix CVE-2025-67477, upgrade your MediaWiki installation to version 1.44.4 or later.
What is stored XSS as it pertains to CVE-2025-67477?
Stored XSS in CVE-2025-67477 refers to malicious scripts being saved in a system message, which can be executed when accessed by users.
Which versions of MediaWiki are affected by CVE-2025-67477?
MediaWiki versions prior to 1.44.4 are affected by CVE-2025-67477.
Is CVE-2025-67477 easy to exploit?
Yes, CVE-2025-67477 is relatively easy to exploit, especially for users with permissions to modify system messages.