CVE-2021-25986
published 2021-11-23CVE-2021-25986: In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.60%
47.5th percentile
In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| django-wiki | django-wiki | >= 0.0.20 < unspecified | unspecified |
| django-wiki | django-wiki | unspecified – 0.7.8 | — |
| django-wiki_project | django-wiki | 0.0.20 – 0.7.8 | — |
| requarks | wiki | >= 0 < 9eaccc7519e4206a4d2f22640882f0737b2da9c5 | 9eaccc7519e4206a4d2f22640882f0737b2da9c5 |
| requarks | wiki | >= 0.0.20 < 0.7.9 | 0.7.9 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cross-site Scripting in django-wiki
ghsa·2021-12-02
CVE-2021-25986 [MEDIUM] CWE-79 Cross-site Scripting in django-wiki
Cross-site Scripting in django-wiki
In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.
OSV
Cross-site Scripting in django-wiki
osv·2021-12-02
CVE-2021-25986 [MEDIUM] Cross-site Scripting in django-wiki
Cross-site Scripting in django-wiki
In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.
OSV
CVE-2021-25986: In Django-wiki, versions 0
osv·2021-11-23
CVE-2021-25986 CVE-2021-25986: In Django-wiki, versions 0
In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/django-wiki/django-wiki/commit/9eaccc7519e4206a4d2f22640882f0737b2da9c5https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25986https://github.com/django-wiki/django-wiki/commit/9eaccc7519e4206a4d2f22640882f0737b2da9c5https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25986
2021-11-23
Published