Web / CMS

Cross-Site Scripting (XSS)

Cross Site Scripting (XSS) in textMessage field in ChatEngine 1.0

Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute

9.0
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS74
PUBLISHED
2023-07-03
CVE IDs
CVE-2023-30320
VENDORS
wliang6
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
ChatEngine 1.0
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.

The Application does not sanitize or escape txtMessage parameter, making it vulnerable to Stored cross-site scripting attacks (XSS). The payload will trigger when a when a victim will vist the chat window page.

Vulnerability details

Vulnerability details

CVE-2023-30320
CWE-79
Critical | 9.0

Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2023-04-01 Reported On

2023-07-06 Made Public On

Fixed On: Not Fixed

Credits

Akshat Singhal