CVE-2022-21650 is a Stored Cross-Site Scripting (XSS) vulnerability affecting Convos, an open-source multi-user chat application. An authenticated attacker can bypass file upload filters by renaming an SVG file with an .html extension, leading to malicious script execution when a user views the uploaded file. With a CVSS score of 5.4 (Medium), this vulnerability requires user interaction and low privileges to exploit, potentially leading to limited impact on confidentiality and integrity. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.48, < 6.52CPE matchmatch criteria | cpe:2.3:a:convos:convos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.