Skip to content
This repository has been archived by the owner on Feb 6, 2023. It is now read-only.

Channel name and description susceptible to XSS

Moderate
nattsw published GHSA-qp62-8m3c-9jgj Oct 5, 2022

Package

Chat (Discourse)

Affected versions

0.9

Patched versions

0.9

Description

Impact

Some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an XSS attack by inserting HTML into them.

Patches

Updating to the latest version of chat will have the patch to fix this.

Severity

Moderate

CVE ID

CVE-2022-39279

Weaknesses

No CWEs