NEOJAPAN ChatLuck Cross-Site Scripting Vulnerability in Chat Rooms
Vulnerability
A cross-site scripting vulnerability has been identified in ChatLuck, a product by NEOJAPAN Inc., specifically in the Chat Rooms feature. This vulnerability allows an attacker to execute arbitrary scripts in the web browser of users accessing the application. It affects ChatLuck versions through 6.6 R2.0.
Impact
Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browsers of users accessing the affected ChatLuck version.
Remediation
Users are advised to update ChatLuck to version 6.7 R1.0 or later. For those using ChatLuck versions 3.6 R1.0 to 6.6 R1.0, the recommended update is to version 6.6 R2.0.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
