
Wagtail CMS 6.4.1 Stored XSS
Wagtail CMS 6.4.1 Stored XSS
This repository demonstrates a Stored XSS vulnerability found in the Wagtail 6.4.1 CMS platform. A malicious JavaScript is embedded in a PDF file, and every time a user clicks on the PDF, an XSS popup appears.
Upload a PDF document that contains a malicious script, like the one provided in this repository.

Access the CMS and locate the malicious PDF.
Click on the PDF link.

The malicious JavaScript will trigger and display an XSS popup every time the PDF is opened.
