An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure dialog for a page containing the malicious node. The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.
Note on duplication
This advisory and GHSA-4qhx-6wrv-5hg2 describe the same underlying defect: a menu node name rendered without escaping in an admin configure dialog. Both were reported by the same researchers and both were addressed in 8.3.8. They were published as two separate records and can no longer be withdrawn, so they are cross referenced here and should be counted as one issue.
An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure dialog for a page containing the malicious node. The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.
Note on duplication
This advisory and GHSA-4qhx-6wrv-5hg2 describe the same underlying defect: a menu node name rendered without escaping in an admin configure dialog. Both were reported by the same researchers and both were addressed in 8.3.8. They were published as two separate records and can no longer be withdrawn, so they are cross referenced here and should be counted as one issue.