Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to inject malicious JavaScript into the content section of pages that would execute once a victim loads the page that contains the payload. This was possible through the injection of a invalid HTML tag with a template injection payload on the next line. This vulnerability is fixed in 2.5.303.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:59:22.635Z

Reserved: 2024-05-07T13:53:00.133Z

Link: CVE-2024-34710

cve-icon Vulnrichment

Updated: 2024-08-02T02:59:22.635Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-20T22:15:08.500

Modified: 2024-11-21T09:19:14.687

Link: CVE-2024-34710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.