(URGENT) Lemmy has an XSS vulnerability in the sidebar
(URGENT) Lemmy has an XSS vulnerability in the sidebar
cross-posted from: https://sh.itjust.works/post/923025
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.
It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.
You're viewing a single thread.
This has nothing to do with XSS, it is a simple HTML injection vulnerability, and it can only be exploited by instance admins.
Also Lemmy.world appears to have been running a custom frontend so it’s hard to say how widespread the affects of this are.
33 1 ReplyYou seem to be following the situation closely. Could you please DM me on Matrix?
9 0 ReplyWorst case scenario, they can steal your Lemmy session, right?
Which isn't super bad for a service like Lemmy. This isn't a social network, so most contact list scams would be useless.
Edit: just read the targets were admins. That IS bad.
2 1 ReplyLemmy isn't a social network? Seems to be one to me.
3 0 ReplyI mean, not in the traditional sense. You don't have your family and friends as Lemmy contacts and share posts with them. It's more anonymous.
3 0 Reply