PT-2021-19814 · Unknown · Matrix-React-Sdk
Mr-Zheev
·
Published
2021-05-17
·
Updated
2022-02-10
·
CVE-2021-32622
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Matrix-React-SDK versions prior to 3.21.0
Description
The issue arises when uploading a file, as the local file preview can lead to the execution of scripts embedded in the uploaded file. This occurs after several user interactions to open the preview in a separate tab. The impact is limited to the local user during the upload process and cannot be exploited remotely or by other users.
Recommendations
For versions prior to 3.21.0, update to version 3.21.0 to resolve the issue.
Fix
Unrestricted File Upload
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Matrix-React-Sdk