CVE-2021-29434
MEDIUMWagtail < 2.11.6, 2.11.0-2.11.7, 2.12.0-2.12.4 - Authenticated Stored Cross-Site Scripting via Rich Text Link URL
Title source: llmDescription
Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents of a rich text field in the admin interface, Wagtail does not apply server-side checks to ensure that link URLs use a valid protocol. A malicious user with access to the admin interface could thus craft a POST request to publish content with `javascript:` URLs containing arbitrary code. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. See referenced GitHub advisory for additional details, including a workaround. Patched versions have been released as Wagtail 2.11.7 (for the LTS 2.11 branch) and Wagtail 2.12.4 (for the current 2.12 branch).
References (2)
Core 2
Core References
Mitigation, Third Party Advisory x_refsource_confirm
https://github.com/wagtail/wagtail/security/advisories/GHSA-wq5h-f9p5-q7fx
Product, Third Party Advisory x_refsource_misc
https://pypi.org/project/wagtail/
Scores
CVSS v3
6.1
EPSS
0.0063
EPSS Percentile
46.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Details
CWE
CWE-79
Status
published
Products (4)
pypi/wagtail
0 - 2.11.7PyPI
torchbox/wagtail
< 2.11.6
torchbox/wagtail
2.11.0 - 2.11.7
torchbox/wagtail
2.12.0 - 2.12.4
Published
Apr 19, 2021
Tracked Since
Feb 18, 2026