PT-2023-22806 · Unknown · Matrix-React-Sdk

Andybala

+1

·

Published

2023-04-25

·

Updated

2024-06-15

·

CVE-2023-30609

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions matrix-react-sdk versions prior to 3.71.0
Description The issue concerns plain text messages containing HTML tags being rendered as HTML in search results. An attacker would need to trick a user into searching for a specific message with an HTML injection payload to exploit this. Although cross-site scripting is not possible due to the hardcoded content security policy, there are exceptions where resources from specific domains can be included, potentially leading to XSS vectors.
Recommendations For versions prior to 3.71.0, update to version 3.71.0 to resolve the issue. As a temporary workaround, restarting the client will clear the HTML injection.

Exploit

Fix

XSS

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-30609
GHSA-XV83-X443-7RMW
OPENSUSE-SU-2024:12884-1
OPENSUSE-SU-2024:12895-1

Affected Products

Matrix-React-Sdk