PT-2020-14332 · Wiki.Js · Wiki.Js

Jtapsl

+1

·

Published

2020-10-26

·

Updated

2020-10-30

·

CVE-2020-15274

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wiki.js versions prior to 2.5.162
Description The issue allows an XSS payload to be injected in a page title and executed via the search results. Although the title is properly escaped in navigation links and the actual page title, it is not escaped in the search results.
Recommendations For versions prior to 2.5.162, update to version 2.5.162 or later, which properly escapes the text content displayed in the search results. As a temporary workaround, consider restricting access to the search functionality until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15274
GHSA-PGJV-84M7-62Q7

Affected Products

Wiki.Js