PT-2024-25540 · Telegram · Telegram Web K

Pedro Batista

·

Published

2024-04-28

·

Updated

2024-07-03

·

CVE-2024-33905

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Telegram WebK versions prior to 2.0.0 (488)
Description A Cross-Site Scripting (XSS) flaw in Telegram WebK allows attackers to gain full account access, potentially jeopardizing data and cryptowallets. The issue stems from the Mini App system and can be exploited via a malicious Mini Web App using the postMessage web app open link event type.
Recommendations For versions prior to 2.0.0 (488), update the web app to version 2.0.0 (488) or later for protection. As a temporary workaround, consider restricting the use of Mini Web Apps until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-33905

Affected Products

Telegram Web K