PT-2021-19933 · Sz.Chat · Sz.Chat
Published
2021-07-19
·
Updated
2021-07-27
·
CVE-2021-3279
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
sz.chat version 4
Description
The issue allows for the injection of web scripts and HTML in the message box. This can potentially lead to malicious activities such as executing unauthorized code or modifying the webpage's content.
Recommendations
For sz.chat version 4, consider disabling the message box feature until a patch is available to prevent the injection of web scripts and HTML. Restrict access to the message box to minimize the risk of exploitation. Avoid using the message box for sending or receiving HTML content until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sz.Chat