Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21650

Опубликовано: 04 янв. 2022
Источник: nvd
CVSS3: 7.6
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS. Also, after uploading a file the XSS attack is triggered upon a user viewing the file. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:convos:convos:*:*:*:*:*:*:*:*
Версия от 6.48 (включая) до 6.52 (исключая)

EPSS

Процентиль: 58%
0.0037
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

EPSS

Процентиль: 58%
0.0037
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79