PT-2020-17853 · Wiki.Js · Wiki.Js
Denandz
·
Published
2020-06-16
·
Updated
2020-06-22
·
CVE-2020-4052
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Wiki.js versions prior to 2.4.107
Description
The issue is caused by an insecure validation mechanism that fails to properly insert v-pre tags into rendered HTML elements containing curly-braces, leading to a stored cross-site scripting vulnerability through template injection. This allows a malicious user to create a crafted wiki page, staging a stored cross-site scripting attack that executes malicious JavaScript when the page is viewed by other users.
Recommendations
For versions prior to 2.4.107, update to version 2.4.107 to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wiki.Js