PT-2018-15413 · Unknown · Chat Anywhere
Published
2018-12-27
·
Updated
2019-01-17
·
CVE-2018-20524
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Chat Anywhere extension version 2.4.0
Description
The issue allows for cross-site scripting (XSS) due to the improper handling of crafted messages containing
<a> tags. This is because a danmuWrapper DIV element in the chatbox-onlydanmu.js file falls outside the scope of the Content Security Policy (CSP), which is designed to protect against such attacks.Recommendations
For Chat Anywhere extension version 2.4.0, consider disabling the
danmuWrapper DIV element in chatbox-onlydanmu.js until a patch is available to prevent potential XSS attacks.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chat Anywhere