CVE-2021-25993: Requarks wiki.js - Stored Cross-Site Scripting (XSS) in markdown editor
Published Dec 29, 2021
·Updated
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.
Affected Software
15 affected components
Requarks Wiki.js>=2.0.1<=2.5.255
Requarks Wiki.js=2.0.0-beta147
Requarks Wiki.js=2.0.0-beta148
Requarks Wiki.js=2.0.0-beta174
Requarks Wiki.js=2.0.0-beta180
Requarks Wiki.js=2.0.0-beta203
Requarks Wiki.js=2.0.0-beta208
Requarks Wiki.js=2.0.0-beta230
Requarks Wiki.js=2.0.0-beta241
Requarks Wiki.js=2.0.0-beta267
Requarks Wiki.js=2.0.0-beta268
Requarks Wiki.js=2.0.0-beta275
Requarks Wiki.js=2.0.0-beta303
Requarks Wiki.js=2.0.0-rc1
Requarks Wiki.js=2.0.0-rc17
Remediation
Information
Update version to 2.5.260 or later
Event History
Dec 29, 2021
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-25993.
2
What is the severity of CVE-2021-25993?
The severity of CVE-2021-25993 is medium, with a CVSS score of 5.4.
3
How does CVE-2021-25993 affect Requarks wiki.js?
CVE-2021-25993 affects Requarks wiki.js versions 2.0.0-beta.147 to 2.5.255.
4
What is the risk of CVE-2021-25993?
CVE-2021-25993 allows a low privileged user to upload a malicious SVG file containing JavaScript, leading to potential token theft.
5
How can I fix CVE-2021-25993?
To fix CVE-2021-25993, upgrade Requarks wiki.js to a version above 2.5.255.