PT-2023-19794 · Misskey · Misskey
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Misskey versions prior to 13.3.1
Description
The issue arises from insufficient validation of the redirect URL during
miauth authentication, allowing arbitrary JavaScript execution when a user allows the link. This can be exploited when users authenticate untrusted apps.Recommendations
For versions prior to 13.3.1, upgrade to version 13.3.1 to resolve the issue.
As a temporary workaround for users unable to upgrade, do not allow authentication of untrusted apps.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Misskey