Логотип exploitDog
bind:CVE-2021-29434
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-29434

Количество 2

Количество 2

nvd логотип

CVE-2021-29434

почти 5 лет назад

Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents of a rich text field in the admin interface, Wagtail does not apply server-side checks to ensure that link URLs use a valid protocol. A malicious user with access to the admin interface could thus craft a POST request to publish content with `javascript:` URLs containing arbitrary code. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. See referenced GitHub advisory for additional details, including a workaround. Patched versions have been released as Wagtail 2.11.7 (for the LTS 2.11 branch) and Wagtail 2.12.4 (for the current 2.12 branch).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wq5h-f9p5-q7fx

почти 5 лет назад

Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-29434

Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents of a rich text field in the admin interface, Wagtail does not apply server-side checks to ensure that link URLs use a valid protocol. A malicious user with access to the admin interface could thus craft a POST request to publish content with `javascript:` URLs containing arbitrary code. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. See referenced GitHub advisory for additional details, including a workaround. Patched versions have been released as Wagtail 2.11.7 (for the LTS 2.11 branch) and Wagtail 2.12.4 (for the current 2.12 branch).

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
github логотип
GHSA-wq5h-f9p5-q7fx

Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields

CVSS3: 6.1
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу