Описание
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to upgrade. Users unable to upgrade should block access to the api/notes/search-by-tag endpoint.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.3.3 (исключая)
cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00344
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89
EPSS
Процентиль: 57%
0.00344
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89