PT-2023-29182 · Citadel · Citadel
Tomoro Taniguchi
·
Publicado
2023-10-04
·
Atualizado
2023-10-10
·
CVE-2023-44272
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Citadel versions prior to 994
Description
A cross-site scripting issue exists. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.
Recommendations
For versions prior to 994, update to version 994 or later to resolve the issue. As a temporary workaround, consider restricting the ability to send instant messages with JavaScript code until a patch is available.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citadel