CVE-2025-7362: MsUpload: Stored Cross-Site Scripting (XSS) via unsanitized msu-continue system message
The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted into the DOM without proper sanitization. The vulnerability occurs in the file upload UI when the same filename is uploaded twice.
This issue affects Mediawiki - MsUpload extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7362?
CVE-2025-7362 is a stored XSS vulnerability that can lead to unauthorized actions or data exposure if exploited.
How do I fix CVE-2025-7362?
To fix CVE-2025-7362, upgrade the MediaWiki MsUpload extension to version 1.39.14 or later, or 1.42.8 or later, or 1.43.3 or later.
Which versions of the MediaWiki MsUpload extension are affected by CVE-2025-7362?
CVE-2025-7362 affects MediaWiki MsUpload extension versions from 1.39.13 to 1.39.X, 1.42.7 to 1.42.X, and 1.43.2 to 1.43.X.
What actions can be taken to mitigate CVE-2025-7362?
Mitigation for CVE-2025-7362 includes disabling the MsUpload extension until an update can be applied.
Is CVE-2025-7362 a critical vulnerability?
While CVE-2025-7362 is a severe issue, its criticality depends on the exposure and context of the MediaWiki deployment.