Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /body2.ghp (POST method), in the mtowho parameter.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-54351 Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /body2.ghp (POST method), in the mtowho parameter.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-05T18:08:06.699Z

Reserved: 2023-08-23T09:39:43.847Z

Link: CVE-2023-4496

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:05.530Z

cve-icon NVD

Status : Modified

Published: 2023-10-04T13:15:26.193

Modified: 2024-11-21T08:35:17.383

Link: CVE-2023-4496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses