XSS Vulnerability in Apache OpenMeetings Chat Functionality
CVE-2017-7663

6.1MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
17 July 2017

Summary

Apache OpenMeetings version 3.2.0 is susceptible to Cross-Site Scripting (XSS) attacks through its chat functionality, affecting both global and room chats. This vulnerability allows an attacker to inject malicious scripts into the chat interface, which can execute in the browsers of users participating in the chat, potentially leading to various security risks. It is imperative for users and administrators to implement mitigations immediately to safeguard their systems from exploitation.

Affected Version(s)

Apache OpenMeetings 3.2.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.