GHSA-g955-vw6w-v6pp

    Dashboard / Vulnerabilities / GHSA-g955-vw6w-v6pp

    GHSA-g955-vw6w-v6pp

    Published: 20 Oct 2025Last Modified: 20 Oct 2025

    Summary: Citizen vulnerable to stored XSS in sticky header button messages

    Details: ### Summary The JS implementation for copying button labels to the sticky header in the Citizen skin unescapes HTML characters, allowing for stored XSS through system messages. ### Details In the `copyButtonAttributes` function in `stickyHeader.js`, when copying the button labels, the `innerHTML` of the new element is set to the `textContent` of the old element: https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/f4cbcecf5aca0ae69966b23d4983f9cb5033f319/resources/skins.citizen.scripts/stickyHeader.js#L29-L41 This unescapes any escaped HTML characters and causes the contents of the system messages to be interpreted as HTML. ### PoC 1. Edit any of the affected messages (`citizen-share`, `citizen-view-history`, `citizen-view-edit`, `nstab-talk`) to the following payload: `<img src="" onerror="alert('Sticky Header Button XSS')">`. 2. Visit any mainpage article in the wiki using the Citizen skin. <img width="495" height="228" alt="image" src="https://github.com/user-attachments/assets/ac75b8e1-b181-4335-9526-17d6b6f8518e" /> <img width="569" height="157" alt="image" src="https://github.com/user-attachments/assets/c052edb9-ff68-4869-9c66-3ec85e7ff68a" /> ### Impact This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. By default, this is the case for the `sysop` group.

    Affected packages

    Package

    Name: starcitizentools/citizen-skin

    Purl: pkg:composer/starcitizentools/citizen-skin

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.3.0
    Fixed -3.9.0

    Affected versions

    v3.3.0
    v3.3.1
    v3.3.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g955-vw6w-v6pp | CVE-DB