Safety vulnerability ID: 38184
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of Wagtail are vulnerable to cross-site scripting (XSS) on the page revision comparison view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could potentially craft a page revision history that, when viewed by a user with higher privileges, could perform actions with that user's credentials. The vulnerability is not exploitable by an ordinary site visitor without access tothe Wagtail admin.
Latest version: 6.4.1
A Django content management system.
~~~~~~~~~~~~~~~~~~
* Fix: CVE-2020-11001 - prevent XSS attack via page revision comparison view (Vlad Gerasimenko, Matt Westcott)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application