CVE-2021-25993: Requarks wiki.js - Stored Cross-Site Scripting (XSS) in markdown editor

Published Dec 29, 2021
·
Updated

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.

Affected Software

15 affected components
Requarks Wiki.js>=2.0.1<=2.5.255
Requarks Wiki.js=2.0.0-beta147
Requarks Wiki.js=2.0.0-beta148
Requarks Wiki.js=2.0.0-beta174
Requarks Wiki.js=2.0.0-beta180
Requarks Wiki.js=2.0.0-beta203
Requarks Wiki.js=2.0.0-beta208
Requarks Wiki.js=2.0.0-beta230
Requarks Wiki.js=2.0.0-beta241
Requarks Wiki.js=2.0.0-beta267
Requarks Wiki.js=2.0.0-beta268
Requarks Wiki.js=2.0.0-beta275
Requarks Wiki.js=2.0.0-beta303
Requarks Wiki.js=2.0.0-rc1
Requarks Wiki.js=2.0.0-rc17

Remediation

Information

Update version to 2.5.260 or later

Event History

Dec 29, 2021
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the vulnerability ID of this vulnerability?

The vulnerability ID is CVE-2021-25993.

2

What is the severity of CVE-2021-25993?

The severity of CVE-2021-25993 is medium, with a CVSS score of 5.4.

3

How does CVE-2021-25993 affect Requarks wiki.js?

CVE-2021-25993 affects Requarks wiki.js versions 2.0.0-beta.147 to 2.5.255.

4

What is the risk of CVE-2021-25993?

CVE-2021-25993 allows a low privileged user to upload a malicious SVG file containing JavaScript, leading to potential token theft.

5

How can I fix CVE-2021-25993?

To fix CVE-2021-25993, upgrade Requarks wiki.js to a version above 2.5.255.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203