PT-2023-22806 · Unknown · Matrix-React-Sdk

Andybala

+1

·

Publicado

2023-04-25

·

Atualizado

2024-06-15

·

CVE-2023-30609

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions matrix-react-sdk versions prior to 3.71.0
Description The issue concerns plain text messages containing HTML tags being rendered as HTML in search results. An attacker would need to trick a user into searching for a specific message with an HTML injection payload to exploit this. Although cross-site scripting is not possible due to the hardcoded content security policy, there are exceptions where resources from specific domains can be included, potentially leading to XSS vectors.
Recommendations For versions prior to 3.71.0, update to version 3.71.0 to resolve the issue. As a temporary workaround, restarting the client will clear the HTML injection.

Exploit

Correção

XSS

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30609
GHSA-XV83-X443-7RMW
OPENSUSE-SU-2024:12884-1
OPENSUSE-SU-2024:12895-1

Produtos afetados

Matrix-React-Sdk