PT-2024-25540 · Telegram · Telegram Web K
Pedro Batista
·
Published
2024-04-28
·
Updated
2024-07-03
·
CVE-2024-33905
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Telegram WebK versions prior to 2.0.0 (488)
Description
A Cross-Site Scripting (XSS) flaw in Telegram WebK allows attackers to gain full account access, potentially jeopardizing data and cryptowallets. The issue stems from the Mini App system and can be exploited via a malicious Mini Web App using the
postMessage web app open link event type.Recommendations
For versions prior to 2.0.0 (488), update the web app to version 2.0.0 (488) or later for protection. As a temporary workaround, consider restricting the use of Mini Web Apps until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telegram Web K