Junglewise Threat Intelligence

CVE-2020-15118: PYSEC-2020-154 - In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagtail.contrib.forms` a

CVE-2020-15118 · Severity: low · CVSS 3.1 · Published 2020-07-20

Technologies: wagtail (PyPI), Wagtail. Vendors: PyPI, Wagtail.

Executive brief

Wagtail is a content management system used by website editors to manage pages and forms. When form pages are configured with help text, unescaped HTML tags within that help text are rendered directly to end users, allowing a malicious editor to inject JavaScript code that could steal credentials, modify page content, or escalate their account privileges. The vulnerability requires admin-level access to Wagtail to exploit, and does not affect ordinary website visitors.

Technical details

This is a cross-site scripting (XSS) vulnerability in the wagtail.contrib.forms app, specifically in how form field help text is rendered when using Django's standard form rendering helpers like form.as_p. The root cause is that HTML tags in help text fields are not escaped before output, despite Wagtail's policy of disallowing arbitrary HTML insertion by editors by default. An authenticated editor with form creation/modification privileges can inject malicious HTML and JavaScript into help text, which will execute in the browsers of end users viewing the form. The vulnerability requires authentication and user interaction (visiting the affected form page) but could enable privilege escalation or account compromise. Patches are available in Wagtail 2.7.4 and 2.9.3, which escape help text output by default; administrators can re-enable HTML via a configuration flag if needed.

Affected products

  • Wagtail Wagtail <2.7.4, 2.8-2.8.2, 2.9-2.9.2

Timeline

  • 2020-07-20: disclosed

References

Related threats