PT-2021-19904 · Muwire · Muwire
Zlatinb
·
Published
2021-07-15
·
Updated
2022-07-02
·
CVE-2021-32750
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MuWire versions prior to 0.8.8
Description
The issue allows an attacker to de-anonymize users of the MuWire desktop client by sending a message with a subject line containing a URL with an HTML image tag. When the MuWire client attempts to fetch the image via clearnet, it exposes the user's IP address.
Recommendations
For versions prior to 0.8.8, update to MuWire 0.8.8 to resolve the issue.
As a temporary workaround, consider disabling the messaging functionality to prevent other users from sending malicious messages.
Exploit
Fix
Information Disclosure
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Muwire