PT-2020-14332 · Wiki.Js · Wiki.Js
Jtapsl
+1
·
Published
2020-10-26
·
Updated
2020-10-30
·
CVE-2020-15274
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wiki.js versions prior to 2.5.162
Description
The issue allows an XSS payload to be injected in a page title and executed via the search results. Although the title is properly escaped in navigation links and the actual page title, it is not escaped in the search results.
Recommendations
For versions prior to 2.5.162, update to version 2.5.162 or later, which properly escapes the text content displayed in the search results. As a temporary workaround, consider restricting access to the search functionality until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wiki.Js