SQL injection of notes/search-by-tag
CVE-2023-24812

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
22 February 2023

What is CVE-2023-24812?

Misskey, an open source decentralized social media platform, is susceptible to SQL injection vulnerabilities in its note search API by tag (notes/search-by-tag). This flaw arises from inadequate parameter validation, allowing attackers to potentially execute arbitrary SQL code. Users should upgrade to version 13.3.3 or later to mitigate this risk. In the interim, those unable to upgrade are advised to block access to the api/notes/search-by-tag endpoint to protect their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

misskey < 13.3.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.