Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1433 | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/VoIP client into a web page. Prior to version 3.71.0, plain text messages containing HTML tags are rendered as HTML in the search results. To exploit this, an attacker needs to trick a user into searching for a specific message containing an HTML injection payload. No cross-site scripting attack is possible due to the hardcoded content security policy. Version 3.71.0 of the SDK patches over the issue. As a workaround, restarting the client will clear the HTML injection. |
Github GHSA |
GHSA-xv83-x443-7rmw | HTML injection in search results via plaintext message highlighting |
Mon, 03 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-03T17:54:55.060Z
Reserved: 2023-04-13T13:25:18.831Z
Link: CVE-2023-30609
Updated: 2024-08-02T14:28:51.679Z
Status : Modified
Published: 2023-04-25T21:15:10.843
Modified: 2024-11-21T08:00:30.010
Link: CVE-2023-30609
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA