PT-2023-29182 · Citadel · Citadel
Tomoro Taniguchi
·
Published
2023-10-04
·
Updated
2023-10-10
·
CVE-2023-44272
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Citadel versions prior to 994
Description
A cross-site scripting issue exists. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.
Recommendations
For versions prior to 994, update to version 994 or later to resolve the issue. As a temporary workaround, consider restricting the ability to send instant messages with JavaScript code until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citadel