PT-2024-26125 · Wiki.Js · Wiki.Js

Et43

·

Published

2024-05-20

·

Updated

2024-06-05

·

CVE-2024-34710

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wiki.js versions prior to 2.5.303
Description A client-side template injection issue was discovered in Wiki.js, a wiki app built on Node.js. This issue could allow an attacker to inject malicious JavaScript into the content section of pages, which would execute when a victim loads the page containing the payload. The injection is possible through the use of an invalid HTML tag with a template injection payload on the next line.
Recommendations For versions prior to 2.5.303, update to version 2.5.303 to resolve the issue. As a temporary workaround, consider restricting the ability to inject custom HTML tags into the content section of pages until the update can be applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34710
GHSA-XJCJ-P2QV-Q3RF
GO-2024-2875

Affected Products

Wiki.Js