Aussie Zone
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
eatham@sh.itjust.works to MetaEnglish · 2 years ago

(URGENT) Lemmy has an XSS vulnerability in the sidebar - sh.itjust.works

sh.itjust.works

external-link
message-square
31
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
23
external-link

(URGENT) Lemmy has an XSS vulnerability in the sidebar - sh.itjust.works

sh.itjust.works

eatham@sh.itjust.works to MetaEnglish · 2 years ago
message-square
31
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar. It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars. [https://sh.itjust.works/pictrs/image/707c0f16-3d5c-4888-b865-34228d968ee6.png]

https://sh.itjust.works/post/923025

  • Gorgritch_Umie_Killa
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    Okay cool, it just worked. No idea what difference waiting overnight made though.

Meta

meta

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Discussion about the aussie.zone instance itself

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 8 users / week
  • 49 users / month
  • 241 users / 6 months
  • 319 local subscribers
  • 670 subscribers
  • 178 Posts
  • 1.7K Comments
  • Modlog
  • mods:
  • admin
  • Lodion 🇦🇺
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org