{"id":"GHSA-xv83-x443-7rmw","summary":"HTML injection in search results via plaintext message highlighting","details":"### Impact\nPlain text messages containing HTML tags are rendered as HTML in the search results. To exploit this, an attacker needs to trick a user into searching for a specific message containing an HTML injection payload.\n\nCross-site scripting is possible by including resources from `recaptcha.net` and `gstatic.com` which are included in the default CSP.\n\nThanks to [Cadence Ember](https://cadence.moe/) for finding the injection and to [S1m](https://github.com/p1gp1g/) for finding possible XSS vectors.\n\n### Patches\nVersion 3.71.0 of the SDK fixes the issue.\n\n### Workarounds\nRestarting the client will clear the injection.","aliases":["CVE-2023-30609"],"modified":"2023-11-08T04:12:25.905467Z","published":"2023-04-25T19:48:11Z","database_specific":{"github_reviewed_at":"2023-04-25T19:48:11Z","nvd_published_at":"2023-04-25T21:15:10Z","cwe_ids":["CWE-74","CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-xv83-x443-7rmw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30609"},{"type":"WEB","url":"https://github.com/matrix-org/matrix-react-sdk/commit/bf182bc94556849d7acdfa0e5fdea2aa129ea826"},{"type":"PACKAGE","url":"https://github.com/matrix-org/matrix-react-sdk"},{"type":"WEB","url":"https://github.com/matrix-org/matrix-react-sdk/releases/tag/v3.71.0"}],"affected":[{"package":{"name":"matrix-react-sdk","ecosystem":"npm","purl":"pkg:npm/matrix-react-sdk"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.71.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-xv83-x443-7rmw/GHSA-xv83-x443-7rmw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L"}]}