5.4

CVE-2021-25993

Exploit

Requarks wiki.js - Stored Cross-Site Scripting (XSS) in markdown editor

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Requarks ≫ Wiki.Js Version >= 2.0.1 <= 2.5.255
Requarks ≫ Wiki.Js Version 2.0.0 Update beta147
Requarks ≫ Wiki.Js Version 2.0.0 Update beta148
Requarks ≫ Wiki.Js Version 2.0.0 Update beta174
Requarks ≫ Wiki.Js Version 2.0.0 Update beta180
Requarks ≫ Wiki.Js Version 2.0.0 Update beta203
Requarks ≫ Wiki.Js Version 2.0.0 Update beta208
Requarks ≫ Wiki.Js Version 2.0.0 Update beta230
Requarks ≫ Wiki.Js Version 2.0.0 Update beta241
Requarks ≫ Wiki.Js Version 2.0.0 Update beta267
Requarks ≫ Wiki.Js Version 2.0.0 Update beta268
Requarks ≫ Wiki.Js Version 2.0.0 Update beta275
Requarks ≫ Wiki.Js Version 2.0.0 Update beta303
Requarks ≫ Wiki.Js Version 2.0.0 Update rc1
Requarks ≫ Wiki.Js Version 2.0.0 Update rc17
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.456
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
vulnerabilitylab@mend.io 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://github.com/Requarks/wiki/commit/5d3e81496fba1f0fbd64eeb855f30f69a9040718
Patch
Third Party Advisory
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25993
Third Party Advisory
Exploit