CVE-2022-39279
Summary
| CVE | CVE-2022-39279 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-06 20:15:00 UTC |
| Updated | 2022-10-11 14:50:00 UTC |
| Description | discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe HTML into them. Version 0.9 has addressed this issue. Users are advised to upgrade. There are no known workarounds for this issue. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Discourse | Discourse-chat | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SECURITY: Ensure channel name and description are always escaped. (#1… · discourse/discourse-chat@2573773 · GitHub | MISC | github.com | |
| Channel name and description susceptible to XSS · Advisory · discourse/discourse-chat · GitHub | CONFIRM | github.com | |
| cve-website | MISC | www.cve.org | |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.