CVE-2021-25016
Chaty < 2.8.3 - Reflected Cross-Site Scripting
Record summary
CVE-2021-25016 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Floating Chat Widget Pro - Chaty Pro | CVE List | 2.8.2 to < 2.8.2 | affected |
Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty | CVE List | 2.8.3 to < 2.8.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMChaty < 2.8.2 - Cross-Site ScriptingCVSS 6.1
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting.
Impact
Attackers can inject malicious JavaScript via reflected XSS in the search parameter, potentially stealing administrator session cookies or accessing chat configuration data.
Remediation
Fixed in 2.8.3
Source: ProjectDiscovery