CVE-2020-11001

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/04/2020
Last modified:
19/11/2024

Description

In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision<br /> comparison view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail<br /> admin could potentially craft a page revision history that, when viewed by a user with higher privileges, could perform<br /> actions with that user&amp;#39;s credentials. The vulnerability is not exploitable by an ordinary site visitor without access to<br /> the Wagtail admin.<br /> <br /> Patched versions have been released as Wagtail 2.7.2 (for the LTS 2.7 branch) and Wagtail 2.8.1 (for the current 2.8 branch).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:* 1.9 (including) 2.7.1 (including)
cpe:2.3:a:torchbox:wagtail:2.8:*:*:*:*:*:*:*