PT-2020-16384 · Bookstack · Bookstack

Percussiveelbow

·

Published

2020-12-09

·

Updated

2020-12-11

·

CVE-2020-26260

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BookStack versions prior to 0.30.5
Description BookStack is a platform for storing and organizing information and documentation. A user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server-side requests and/or have access to a wider scope of files within the BookStack file storage locations.
Recommendations For versions prior to 0.30.5, upgrade to BookStack v0.30.5 to address the issue. As a temporary workaround, consider limiting page edit permissions to only those that are trusted until you can upgrade.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26260
GHSA-8WFC-W2R5-X7CR

Affected Products

Bookstack