Executive brief
Wagtail is a content management system used to build and manage websites. A security flaw allows users with 'editor' permissions to insert malicious scripts into certain text fields. If exploited, this could lead to unauthorized actions being performed in the browser of other site visitors or administrators, potentially compromising user sessions or site integrity.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Wagtail's StreamField component. When the '{% include_block %}' template tag is used to render plain-text blocks like 'CharBlock' or 'TextBlock' without a specific rendering template, the output is not properly HTML-escaped. An attacker with 'editor' access can input malicious scripts into these fields, which are then executed when the content is viewed by others. The issue is rooted in the 'FieldBlock' class and its derivatives. Patches are available in versions 2.11.8, 2.12.5, and 2.13.2.
Affected products
- Wagtail Wagtail < 2.11.8, >= 2.12 < 2.12.5, >= 2.13 < 2.13.2
Timeline
- 2021-06-17: disclosed
- 2021-06-17: advisory
- 2021-06-17: patched
References
- https://github.com/wagtail/wagtail/security/advisories/GHSA-xfrw-hxr5-ghqf
- https://github.com/wagtail/wagtail/releases/tag/v2.11.8
- https://github.com/wagtail/wagtail/releases/tag/v2.12.5
- https://github.com/wagtail/wagtail/releases/tag/v2.13.2
- https://github.com/pypa/advisory-database/tree/main/vulns/wagtail/PYSEC-2021-103.yaml