PT-2023-19794 · Misskey · Misskey

·

CVE-2023-24810

·

Publicado

2023-02-22

·

Atualizado

2023-03-03

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Misskey versions prior to 13.3.1
Description The issue arises from insufficient validation of the redirect URL during miauth authentication, allowing arbitrary JavaScript execution when a user allows the link. This can be exploited when users authenticate untrusted apps.
Recommendations For versions prior to 13.3.1, upgrade to version 13.3.1 to resolve the issue. As a temporary workaround for users unable to upgrade, do not allow authentication of untrusted apps.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-24810
GHSA-CC6R-CHGR-8R5M

Produtos afetados

Misskey