CVE-2021-43842: Stored XSS via SVG file upload in Wiki.js
Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the SVG is viewed directly by other users. Scripts do not execute when loaded inside a page via normal <img> tags. Commit 5d3e81496fba1f0fbd64eeb855f30f69a9040718 fixes this vulnerability by adding an optional (enabled by default) SVG sanitization step to all file uploads that match the SVG mime type. As a workaround, disable file upload for all non-trusted users. Wiki.js version 2.5.260 is the first production version to contain a patch. Version 2.5.258 is the first development build to contain a patch and is available only as a Docker image as requarks/wiki:canary-2.5.258.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-43842?
CVE-2021-43842 is a vulnerability in Wiki.js versions 2.5.257 and earlier that allows for stored cross-site scripting (XSS) attacks.
How severe is the vulnerability CVE-2021-43842?
The severity of CVE-2021-43842 is medium with a CVSS score of 5.4.
How can I exploit CVE-2021-43842?
To exploit CVE-2021-43842, you need to upload a crafted SVG file as a malicious user in Wiki.js.
How do I fix CVE-2021-43842?
To fix CVE-2021-43842, update Wiki.js to version 2.5.260 or later.
Where can I find more information about CVE-2021-43842?
You can find more information about CVE-2021-43842 on the Requarks Wiki.js GitHub page, including the advisory and the fix in the release notes.