Impact
The vulnerability is a Self‑Cross‑Site Scripting (Self‑XSS) bug that occurs when a malicious script is embedded in the ‘name’ parameter during the chat initialization process. Because the input is not properly sanitized, the script is executed in the user’s own browser session when the payload is entered. The likely attack vector is for an attacker to supply a malformed name value when starting a chat, and the demonstrated impact is limited to the user who enters and executes the payload, potentially enabling credential theft, session hijacking, or other client‑side malicious actions.
Affected Systems
RD Station Conversas Tallos Chat across all supported platforms—Android, iOS, Linux, macOS, and Windows—and all current product versions are listed as vulnerable.
Risk and Exploitability
EPSS score is less than 1%, suggesting a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV. Because the flaw is client‑side, it does not permit remote code execution on the server, but it can compromise the browser of the user who enters the malicious payload. Successful exploitation requires an attacker’s ability to inject a malicious name value into the initialization request, and the payload is executed in the user’s own browser session.
OpenCVE Enrichment