The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.
References
Configurations
History
14 Oct 2025, 20:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:star-citizen:embedvideo:*:*:*:*:*:mediawiki:*:* | |
First Time |
Star-citizen embedvideo
Star-citizen |
|
References | () https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/ext.embedVideo.videolink.js#L5-L20 - Product | |
References | () https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/modules/iframe.js#L139-L155 - Product | |
References | () https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/4e075d3dc9a15a3ee53f449a684d5ab847e52f01 - Patch | |
References | () https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-4j5h-mvj3-m48v - Exploit, Vendor Advisory |
25 Sep 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-4j5h-mvj3-m48v - |
25 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-25 14:15
Updated : 2025-10-14 20:02
NVD link : CVE-2025-59839
Mitre link : CVE-2025-59839
CVE.ORG link : CVE-2025-59839
JSON object : View
Products Affected
star-citizen
- embedvideo
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')