Security Games Windows Linux Android IOS News Reviews AI

CVE-2022-21649 Vulnerability Details

  /     /     /  

CVE-2022-21649 Metadata Quick Info

CVE Published: 04/01/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: GitHub_M | Vendor: convos-chat | Product: convos
Status : PUBLISHED

CVE-2022-21649 Description

Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

Metrics

CVSS Version: 3.1 | Base Score: 7.6 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* CHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-79
CWE Name: CWE-79: Improper Neutralization of Input During Web Page Generation ( Cross-site Scripting )
Source: convos-chat

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).

Last added CVEs

▸ CVE-2024-9999 ◂
Discovered: 12/11/2024
Status: PUBLISHED

▸ CVE-2024-9997 ◂
Discovered: 29/10/2024
Status: PUBLISHED

▸ CVE-2024-9996 ◂
Discovered: 29/10/2024
Status: PUBLISHED



Tags:
CVE-2022-21649 Vulnerability Details


Free Software Downloads, News and Reviews
Info
Legal
  • GDPR
  • Contact
  • ToS
  • Sitemap
Partners
  • Curs-cybersecurity.ro
Last News
  • 01/07/2025 ArcSight prepares for ...
  • 01/07/2025 Samsung Epic 4G: ...
  • 01/07/2025 Many third-party software ...
facebook twitter youtube linkedin

Copyright © 2025 Free Downloads Now