PT-2023-19794 · Misskey · Misskey
Ry0Tak
·
Published
2023-02-22
·
Updated
2023-03-03
·
CVE-2023-24810
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Misskey versions prior to 13.3.1
Description
The issue arises from insufficient validation of the redirect URL during
miauth authentication, allowing arbitrary JavaScript execution when a user allows the link. This can be exploited when users authenticate untrusted apps.Recommendations
For versions prior to 13.3.1, upgrade to version 13.3.1 to resolve the issue.
As a temporary workaround for users unable to upgrade, do not allow authentication of untrusted apps.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misskey