PT-2021-19904 · Muwire · Muwire

Zlatinb

·

Published

2021-07-15

·

Updated

2022-07-02

·

CVE-2021-32750

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MuWire versions prior to 0.8.8
Description The issue allows an attacker to de-anonymize users of the MuWire desktop client by sending a message with a subject line containing a URL with an HTML image tag. When the MuWire client attempts to fetch the image via clearnet, it exposes the user's IP address.
Recommendations For versions prior to 0.8.8, update to MuWire 0.8.8 to resolve the issue. As a temporary workaround, consider disabling the messaging functionality to prevent other users from sending malicious messages.

Exploit

Fix

Information Disclosure

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32750
GHSA-68XH-9H7W-64QG

Affected Products

Muwire