Aussie Zone
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
eatham@sh.itjust.works to MetaEnglish · 2 years ago

(URGENT) Lemmy has an XSS vulnerability in the sidebar - sh.itjust.works

sh.itjust.works

external-link
message-square
31
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
23
external-link

(URGENT) Lemmy has an XSS vulnerability in the sidebar - sh.itjust.works

sh.itjust.works

eatham@sh.itjust.works to MetaEnglish · 2 years ago
message-square
31
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar. It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars. [https://sh.itjust.works/pictrs/image/707c0f16-3d5c-4888-b865-34228d968ee6.png]

https://sh.itjust.works/post/923025

  • Aesecakes
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    Thank you, that worked!

    • Lodion 🇦🇺MA
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 years ago

      Excellent 🙂

      • cuppaconcrete
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 years ago

        You are one of the best admins I’ve met in my coupla decades of internet usage. I love ya work mate and if you ever want a hand from a fellow sysadmin hit me up.

        • Lodion 🇦🇺MA
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          aww thanks 😇

Meta

meta

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Discussion about the aussie.zone instance itself

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 48 users / month
  • 241 users / 6 months
  • 319 local subscribers
  • 672 subscribers
  • 178 Posts
  • 1.7K Comments
  • Modlog
  • mods:
  • admin
  • Lodion 🇦🇺
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org