3.5 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
0.001 Low
EPSS
Percentile
39.2%
Wagtail release notes:
CVE-2020-11001: Possible XSS attack via page revision comparison view
This release addresses a cross-site scripting (XSS) vulnerability on
the page revision comparison view within the Wagtail admin interface. A
user with a limited-permission editor account for the Wagtail admin
could potentially craft a page revision history that, when viewed by a
user with higher privileges, could perform actions with that user
credentials. The vulnerability is not exploitable by an ordinary site
visitor without access to the Wagtail admin.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
FreeBSD | any | noarch | py35-wagtail | < 2.7.2 | UNKNOWN |
FreeBSD | any | noarch | py36-wagtail | < 2.7.2 | UNKNOWN |
FreeBSD | any | noarch | py37-wagtail | < 2.7.2 | UNKNOWN |
FreeBSD | any | noarch | py38-wagtail | < 2.7.2 | UNKNOWN |
3.5 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
0.001 Low
EPSS
Percentile
39.2%