PT-2018-15413 · Unknown · Chat Anywhere

Publicado

2018-12-27

·

Atualizado

2019-01-17

·

CVE-2018-20524

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chat Anywhere extension version 2.4.0
Description The issue allows for cross-site scripting (XSS) due to the improper handling of crafted messages containing <a> tags. This is because a danmuWrapper DIV element in the chatbox-onlydanmu.js file falls outside the scope of the Content Security Policy (CSP), which is designed to protect against such attacks.
Recommendations For Chat Anywhere extension version 2.4.0, consider disabling the danmuWrapper DIV element in chatbox-onlydanmu.js until a patch is available to prevent potential XSS attacks.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20524

Produtos afetados

Chat Anywhere