Vulnerability record · CVE-2020-26211 · published 3 November 2020
CVE-2020-26211: Bookstackapp bookstack cross-site scripting vulnerability
Bookstackapp · Bookstack
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with permissions to edit a page could insert a particular meta tag which could be used to silently redirect users to a alternative location upon visit of a page. Dangerous content may remain in the database but will be removed before being displayed on a page. If you think this could have been exploited the linked advisory provides a SQL query to test. As a workaround without upgrading, page edit permissions could be limited to only those that are trusted until you can upgrade although this will not address existing exploitation of this vulnerability. The issue is fixed in BookStack version 0.30.4.
Description
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with permissions to edit a page could insert a particular meta tag which could be used to silently redirect users to a alternative location upon visit of a page. Dangerous content may remain in the database but will be removed before being displayed on a page. If you think this could have been exploited the linked advisory provides a SQL query to test. As a workaround without upgrading, page edit permissions could be limited to only those that are trusted until you can upgrade although this will not address existing exploitation of this vulnerability. The issue is fixed in BookStack version 0.30.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/BookStackApp/BookStack/commit/bbd1384acbe7e52c21f89af69f2dc391c95dbf54 | PatchThird Party Advisory |
| https://github.com/BookStackApp/BookStack/releases/tag/v0.30.4 | Release NotesThird Party Advisory |
| https://github.com/BookStackApp/BookStack/security/advisories/GHSA-r2cf-8778-3jgp | Third Party Advisory |
| https://www.bookstackapp.com/blog/beta-release-v0-30-4/ | PatchVendor Advisory |
| https://github.com/BookStackApp/BookStack/commit/bbd1384acbe7e52c21f89af69f2dc391c95dbf54 | PatchThird Party Advisory |
| https://github.com/BookStackApp/BookStack/releases/tag/v0.30.4 | Release NotesThird Party Advisory |
| https://github.com/BookStackApp/BookStack/security/advisories/GHSA-r2cf-8778-3jgp | Third Party Advisory |
| https://www.bookstackapp.com/blog/beta-release-v0-30-4/ | PatchVendor Advisory |
Track CVE-2020-26211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-26211), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.