Uploaded image for project: 'Openmeetings'
  1. Openmeetings
  2. OPENMEETINGS-1379

XSS in Chat window leading to DOS

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Fixed
    • 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.1.0, 3.1.1, 3.1.2
    • 3.1.2, 3.2.0, 4.0.0
    • UI

    Description

      The chat window can execute XSS payloads, thus one can infect all the users who have joined the room/meeting. The XSS is persistent and that can lead to Denial of Service.

      A simple popup which alerts 9 can make it hard for other user to use it.

      One can check the POC by trying to log-in at the demo server provided: https://om.alteametasoft.com/openmeetings/

      Attachments

        Activity

          People

            solomax Maxim Solodovnik
            subho007 Subho Halder
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: