vulnerability

FreeBSD: VID-c70c3dc3-258c-11ee-b37b-901b0e9408dc (CVE-2023-37259): element-web -- Cross site scripting in Export Chat feature

Severity
5
CVSS
(AV:A/AC:M/Au:S/C:C/I:N/A:N)
Published
Jul 18, 2023
Added
Jul 19, 2023
Modified
Dec 10, 2025

Description

Matrix Developers reports: The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored XSS.

Solution

freebsd-upgrade-package-element-web
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.