PT-2021-19933 · Sz.Chat · Sz.Chat

Published

2021-07-19

·

Updated

2021-07-27

·

CVE-2021-3279

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions sz.chat version 4
Description The issue allows for the injection of web scripts and HTML in the message box. This can potentially lead to malicious activities such as executing unauthorized code or modifying the webpage's content.
Recommendations For sz.chat version 4, consider disabling the message box feature until a patch is available to prevent the injection of web scripts and HTML. Restrict access to the message box to minimize the risk of exploitation. Avoid using the message box for sending or receiving HTML content until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3279

Affected Products

Sz.Chat