Executive brief
django-wiki is a collaborative wiki application for Django-based projects. An attacker with page-editing permissions can inject malicious JavaScript into page titles, which is then executed when other users receive notifications about those changes. This allows theft of session cookies, account takeover, and malware delivery to affected users.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Notifications section, where user-supplied input in page titles is not properly sanitized before being rendered in notification messages. An authenticated attacker with page-editing privileges can craft a malicious title containing JavaScript payloads that execute in the browsers of notification recipients. The vulnerability affects versions 0.0.20 through 0.7.8. A fix was merged in pull request #1148 to properly escape HTML elements when building notifications. No authentication bypass is required for exploitation beyond normal page-edit permissions.
Affected products
- django-wiki django-wiki 0.0.20 to 0.7.8
Timeline
- 2021-12-02: disclosed
- 2021-11-16: patched: Fix merged in PR #1148