CVE-2025-67483: Theoretical i18n XSS in mediawiki.page.preview.js when a page has multiple protection levels
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Page.Preview.Js.
This issue affects MediaWiki: from before 1.43.6, 1.44.3, 1.45.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67483?
CVE-2025-67483 is classified as a moderate severity vulnerability due to its potential for exploitation through XSS.
How do I fix CVE-2025-67483?
To fix CVE-2025-67483, upgrade MediaWiki to version 1.43.7 or later, or a version between 1.44.3 and 1.45.1.
What is the impact of CVE-2025-67483 on MediaWiki?
CVE-2025-67483 allows for improper neutralization of input, leading to possible cross-site scripting (XSS) attacks when rendering pages with varying protection levels.
Which versions of MediaWiki are affected by CVE-2025-67483?
MediaWiki versions up to 1.43.6 and those between 1.44.3 and 1.45.1 are affected by CVE-2025-67483.
Is CVE-2025-67483 a publicly known vulnerability?
Yes, CVE-2025-67483 is a publicly disclosed vulnerability associated with MediaWiki's page preview functionality.