Skip to content
This repository has been archived by the owner on Feb 6, 2023. It is now read-only.

XSS issue for channel names and descriptions

Moderate
pmusaraj published GHSA-3vf2-wrjx-p6xj Aug 29, 2022

Package

Discourse (Discourse)

Affected versions

0.9

Patched versions

0.9

Description

Impact

Users of discourse chat can be affected by admin users inserting HTML into chat titles and descriptions, causing an XSS attack.

Patches

Updating to the latest version of chat will have the patch to fix this.

Severity

Moderate

CVE ID

CVE-2022-36057

Weaknesses