CVE-2021-29434

MEDIUM

Wagtail < 2.11.6, 2.11.0-2.11.7, 2.12.0-2.12.4 - Authenticated Stored Cross-Site Scripting via Rich Text Link URL

Title source: llm
STIX 2.1

Description

Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents of a rich text field in the admin interface, Wagtail does not apply server-side checks to ensure that link URLs use a valid protocol. A malicious user with access to the admin interface could thus craft a POST request to publish content with `javascript:` URLs containing arbitrary code. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. See referenced GitHub advisory for additional details, including a workaround. Patched versions have been released as Wagtail 2.11.7 (for the LTS 2.11 branch) and Wagtail 2.12.4 (for the current 2.12 branch).

References (2)

Core 2
Core References
Mitigation, Third Party Advisory x_refsource_confirm
https://github.com/wagtail/wagtail/security/advisories/GHSA-wq5h-f9p5-q7fx
Product, Third Party Advisory x_refsource_misc
https://pypi.org/project/wagtail/

Scores

CVSS v3 6.1
EPSS 0.0063
EPSS Percentile 46.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-79
Status published
Products (4)
pypi/wagtail 0 - 2.11.7PyPI
torchbox/wagtail < 2.11.6
torchbox/wagtail 2.11.0 - 2.11.7
torchbox/wagtail 2.12.0 - 2.12.4
Published Apr 19, 2021
Tracked Since Feb 18, 2026