Citadel · Citadel · CVE-2023-44272
**Name of the Vulnerable Software and Affected Versions**
Citadel versions prior to 994
**Description**
A cross-site scripting issue exists. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.
**Recommendations**
For versions prior to 994, update to version 994 or later to resolve the issue. As a temporary workaround, consider restricting the ability to send instant messages with JavaScript code until a patch is available.