Description
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0723 | Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3. |
Github GHSA |
GHSA-26q7-g57v-mxcp | HTML Injection in shout |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T16:58:10.449Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-16043
No data.
Status : Modified
Published: 2018-06-04T19:29:02.147
Modified: 2024-11-21T03:15:42.740
Link: CVE-2017-16043
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA