Impact
The vulnerability is a stored cross‑site scripting flaw that arises when a malicious script is embedded in the ‘name’ parameter during the chat initialization process. Because the input is not properly sanitized, the script is persisted and later rendered to any participant who views the chat, allowing an attacker to execute arbitrary JavaScript in the context of the application. The likely attack vector is for an attacker to supply a malformed name value when starting a chat or otherwise influence the initialization data, and the impact is confined to the browsers of users who load the stored data, potentially enabling credential theft, session hijacking, or other client‑side malicious actions.
Affected Systems
RD Station Conversas Tallos Chat across all supported platforms—Android, iOS, Linux, macOS, and Windows—and all current product versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV. Because the flaw is client‑side, it does not permit remote code execution on the server, but it can compromise the browsers of any support agent or user who views the stored chat content. Successful exploitation requires an attacker’s ability to inject a malicious name value into the initialization request and for that content to be subsequently rendered to other users.
OpenCVE Enrichment