VDB
Sign up
MEDIUM6.5

GHSA-jwr7-992g-68mh

starcitizentools/citizen-skin allows stored XSS in preference menu heading messages

Quick fix

GHSA-jwr7-992g-68mh — starcitizentools/citizen-skin: upgrade to the fixed version with the command below.

composer require starcitizentools/citizen-skin:^3.3.1

Details

### Summary Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.

### Details The `innerHtml` of the label div is set to the `textContent` of the label, essentially unsanitizing the system messages: https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/407052e7069bdeae927d6f1a2a1c9a45b473bf9a/resources/skins.citizen.preferences/addPortlet.polyfill.js#L18

### PoC 1. Edit `citizen-feature-custom-font-size-name` (or any other message displayed in a heading in the preferences menu) to `<img src="" onerror="alert('citizen-feature-custom-font-size-name')">` (script tags don't work here due to the way the HTML is inserted) 2. Open the preferences menu ![image](https://github.com/user-attachments/assets/b75f100d-09cc-443c-b635-e9d6ab48d133)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/starcitizentools/citizen-skin
Introduced in: 2.13.0Fixed in: 3.3.1
Fixcomposer require starcitizentools/citizen-skin:^3.3.1

References