Web / CMS

Cross-Site Scripting (XSS)

Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0

Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0 ThThe Application does not sanitize or escape username parameter, making it vulnerable to Stored cross-site

5.4
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS76
PUBLISHED
2023-07-05
CVE IDs
CVE-2023-30322
VENDORS
wliang6
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
ChatEngine 1.0
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0

ThThe Application does not sanitize or escape username parameter, making it vulnerable to Stored cross-site scripting attacks (XSS). The payload will trigger when a when a victim will visit the chatwindow page.

Vulnerability details

Vulnerability details

CVE-2023-30322
CWE-79
Medium | 5.4

Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0 ThThe Application does not sanitize or escape username parameter, making it vulnerable to Stored cross-site scripting attacks (XSS).

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2023-04-01 Reported On

2023-07-06 Made Public On

Fixed On: Not Fixed

Credits

Akshat Singhal