First published: Tue Sep 06 2022(Updated: )
Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a patch for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse-chat | <0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36057 is classified as a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2022-36057, upgrade the Discourse-Chat plugin to version 0.9 or later.
CVE-2022-36057 is a Cross-Site Scripting (XSS) vulnerability affecting the Discourse-Chat plugin.
Users of the Discourse-Chat plugin using versions prior to 0.9 are affected by CVE-2022-36057.
Attackers exploiting CVE-2022-36057 can insert malicious HTML into chat titles and descriptions to execute scripts in the context of users' browsers.