PT-2021-19814 · Unknown · Matrix-React-Sdk

Mr-Zheev

·

Published

2021-05-17

·

Updated

2022-02-10

·

CVE-2021-32622

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Matrix-React-SDK versions prior to 3.21.0
Description The issue arises when uploading a file, as the local file preview can lead to the execution of scripts embedded in the uploaded file. This occurs after several user interactions to open the preview in a separate tab. The impact is limited to the local user during the upload process and cannot be exploited remotely or by other users.
Recommendations For versions prior to 3.21.0, update to version 3.21.0 to resolve the issue.

Fix

Unrestricted File Upload

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32622
GHSA-8796-GC9J-63RV
GHSA-CG57-P69R-3M7P

Affected Products

Matrix-React-Sdk