Vulnerability Description
The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Urlchatbox | Chat Anywhere | 2.4.0 |
Related Weaknesses (CWE)
References
- https://vul.su.ki/posts/Chat_Anywhere_2.4.0_XSS.md/ExploitThird Party Advisory
- https://vul.su.ki/posts/Chat_Anywhere_2.4.0_XSS.md/ExploitThird Party Advisory
FAQ
What is CVE-2018-20524?
CVE-2018-20524 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Pol...
How severe is CVE-2018-20524?
CVE-2018-20524 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20524?
Check the references section above for vendor advisories and patch information. Affected products include: Urlchatbox Chat Anywhere.