CVE-2022-39279

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-39279
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-39279.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-39279
Aliases
  • GHSA-qp62-8m3c-9jgj
Published
2022-10-06T00:00:00Z
Modified
2025-11-28T04:54:10.146813Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Discourse-chat plugin susceptible to XSS in channel name and description
Details

discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe HTML into them. Version 0.9 has addressed this issue. Users are advised to upgrade. There are no known workarounds for this issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39279.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/discourse/discourse-chat

Affected ranges

Type
GIT
Repo
https://github.com/discourse/discourse-chat
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed