The CheckUser-UserInfoCard feature is vulnerable to message key XSS through several messages
Problem messages
| Message name(s) | Override using stored XSS | Resulting alert showing that JavaScript was run |
|---|---|---|
| All group-* messages | ||
| checkuser-userinfocard-groups | ||
| All global group messages | ||
| checkuser-userinfocard-global-groups | ||
Acceptance criteria
- CheckUser-UserInfoCard is no longer vulnerable to message key stored XSS







