CVE-2022-21649 Information

Description

Convos is an open source multi-user chat that runs in a web browser. Characters starting with \https://\ in the chat window create an tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for <\ or >\ but escaping for double quotes does not exist. Through this vulnerability an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/convos-chat/convos/security/advisories/GHSA-xmpj-xwm3-vww7 https://github.com/convos-chat/convos/commit/86b2193de375005ba71d9dd53843562c6ac1847c https://www.huntr.dev/bounties/4532a0ac-4e7c-4fcf-9fe3-630e132325c0/ https://blog.pocas.kr/2021/12/30/2021-12-30-s-xss-convos-chat/#Second-vulnerability

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: