CVE-2022-21649
04.01.2022, 21:15
Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an <a> tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.
Cross-site Scripting
Vendor | Product | Version |
---|---|---|
convos | convos | 𝑥 < 6.52 |
𝑥
= Vulnerable software versions
References