PT-2020-12483 · Wagtail · Wagtail
Vlad Gerasimenko
·
Published
2020-04-14
·
Updated
2024-11-19
·
CVE-2020-11001
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wagtail versions prior to 2.7.2 and prior to 2.8.1
Description
A cross-site scripting (XSS) vulnerability exists on the page revision comparison view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could potentially craft a page revision history that, when viewed by a user with higher privileges, could perform actions with that user's credentials. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.
Recommendations
For versions prior to 2.7.2, update to Wagtail 2.7.2.
For versions prior to 2.8.1, update to Wagtail 2.8.1.
As a temporary workaround, site owners who are unable to upgrade to the new versions can disable the revision comparison view by adding a URL route to the top of their project's
urls.py configuration to redirect the revision comparison view to the admin dashboard.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wagtail