High severity7.6NVD Advisory· Published Jan 4, 2022· Updated Jun 17, 2026
CVE-2022-21649
CVE-2022-21649
Description
Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: >= 6.49, < 6.52
Patches
Vulnerability mechanics
References
4- github.com/convos-chat/convos/commit/86b2193de375005ba71d9dd53843562c6ac1847cnvdPatchThird Party Advisory
- github.com/convos-chat/convos/security/advisories/GHSA-xmpj-xwm3-vww7nvdPatchThird Party Advisory
- www.huntr.dev/bounties/4532a0ac-4e7c-4fcf-9fe3-630e132325c0/nvdExploitPatchThird Party Advisory
- blog.pocas.kr/2021/12/30/2021-12-30-s-xss-convos-chat/nvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.