GHSA-8c6x-g4fw-8rf4

Suggest an improvement
Source
https://github.com/advisories/GHSA-8c6x-g4fw-8rf4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-8c6x-g4fw-8rf4/GHSA-8c6x-g4fw-8rf4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8c6x-g4fw-8rf4
Published
2023-07-10T21:54:36Z
Modified
2024-12-06T05:39:21Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Whatsapp-Chat-Exporter has Cross-Site Scripting vulnerability in HTML output of chats.
Details

Impact

A Cross-Site Scripting (XSS) vulnerability was found in the HTML output of chats. XSS is intended to be mitigated by Jinja's escape function. However, autoescape=True was missing when setting the environment. Although the actual impact is low, considering the HTML file is being viewed offline, an adversary may still be able to inject malicious payloads into the chat through WhatsApp. All users are affected.

Patches

The vulnerability is patched in 0.9.5. All users are strongly advised to update the exporter to the latest version.

Workarounds

No workaround is available. Please update the exporter to the latest version.

References

https://github.com/KnugiHK/WhatsApp-Chat-Exporter/commit/bfdc68cd6ad53ceecf132773f9aaba50dd80fe79 https://owasp.org/www-community/attacks/xss/

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-07-10T21:54:36Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / whatsapp-chat-exporter

Package

Name
whatsapp-chat-exporter
View open source insights on deps.dev
Purl
pkg:pypi/whatsapp-chat-exporter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.5

Affected versions

0.*
0.6
0.7.0
0.8.0
0.8.1
0.8.2
0.8.5
0.9.0
0.9.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-8c6x-g4fw-8rf4/GHSA-8c6x-g4fw-8rf4.json"