PT-2018-15413 · Unknown · Chat Anywhere

Published

2018-12-27

·

Updated

2019-01-17

·

CVE-2018-20524

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chat Anywhere extension version 2.4.0
Description The issue allows for cross-site scripting (XSS) due to the improper handling of crafted messages containing <a> tags. This is because a danmuWrapper DIV element in the chatbox-onlydanmu.js file falls outside the scope of the Content Security Policy (CSP), which is designed to protect against such attacks.
Recommendations For Chat Anywhere extension version 2.4.0, consider disabling the danmuWrapper DIV element in chatbox-onlydanmu.js until a patch is available to prevent potential XSS attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20524

Affected Products

Chat Anywhere