Executive brief
A vulnerability exists in the djangocms-attributes-field library, which is used by the django CMS platform to manage HTML element attributes. An attacker with high-level administrative privileges can inject malicious scripts into these attribute fields. When other users or administrators view the affected pages, the script executes in their browser, potentially allowing the attacker to steal sensitive session information or perform unauthorized actions.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in djangocms-attributes-field due to improper neutralization of input during web page generation (CWE-79). The vulnerability is located in the component responsible for handling JSON-based HTML element attributes. An attacker with high privileges (PR:H) can submit crafted input that is stored in the database and later rendered without sufficient sanitization. This can lead to a scope change (S:C) where the attacker's script executes in the context of other users' sessions. The issue is resolved in version 4.0.0, which introduced improved form field validation.
Affected products
- django CMS Association djangocms-attributes-field < 4.0.0
Timeline
- 2024-11-19: patched: Fix committed to repository
- 2024-11-20: disclosed: Public advisory published
References
- https://github.com/django-cms/djangocms-attributes-field/commit/fe68d29ab78db5885bc31b67cf0537f1f02b33ad
- https://iltosec.com/blog/post/djangocms-attributes-field-300-stored-xss-vulnerability
- https://pypi.org/project/djangocms-attributes-field/
- https://www.django-cms.org/en/blog/2024/11/19/security-updates-for-django-filer-and-django-cms-attributes-field
- https://www.usom.gov.tr/bildirim/tr-24-1864