CVE-2023-37259
Last modified
CVE-2023-37259 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored Cross site scripting (XSS). EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored Cross site scripting (XSS). Since the Export Chat feature generates a separate document, an attacker can only inject code run from the `null` origin, restricting the impact. However, the attacker can still potentially use the XSS to leak message contents. A malicious homeserver is a potential attacker since the affected inputs are controllable server-side. This issue has been addressed in commit `22fcd34c60` which is included in release version 3.76.0. Users are advised to upgrade. The only known workaround for this issue is to disable or to not use the Export Chat feature.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Matrix-React-Sdk Project | Matrix-React-Sdk | >= 3.32.0, < 3.76.0 | — |
| Matrix-React-Sdk Project | Matrix-React-Sdk | 3.76.0 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37259?
How severe is CVE-2023-37259?
How do I fix CVE-2023-37259?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-37251An issue was discovered in the GoogleAnalyticsMetrics extens…6.1
- CVE-2023-37254An issue was discovered in the Cargo extension for MediaWiki…6.1
- CVE-2023-37255An issue was discovered in the CheckUser extension for Media…6.1
- CVE-2023-37256An issue was discovered in the Cargo extension for MediaWiki…6.1
- CVE-2023-37257DataEase is an open source data visualization analysis tool.…5.4
- CVE-2023-37258DataEase is an open source data visualization analysis tool.…9.8
- CVE-2023-3726OCSInventory allow stored email template with special charac…6.9
- CVE-2023-37260league/oauth2-server is an implementation of an OAuth 2.0 au…7.5
- CVE-2023-37261OpenComputers is a Minecraft mod that adds programmable comp…8.8
- CVE-2023-37262CC: Tweaked is a mod for Minecraft which adds programmable c…8.8
- CVE-2023-37263Strapi is the an open-source headless content management sys…2.7
- CVE-2023-37264Tekton Pipelines project provides k8s-style resources for de…4.3
Are you affected by CVE-2023-37259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
