SQL injection of notes/search-by-tag
CVE-2023-24812
8.8HIGH
What is CVE-2023-24812?
Misskey, an open source decentralized social media platform, is susceptible to SQL injection vulnerabilities in its note search API by tag (notes/search-by-tag). This flaw arises from inadequate parameter validation, allowing attackers to potentially execute arbitrary SQL code. Users should upgrade to version 13.3.3 or later to mitigate this risk. In the interim, those unable to upgrade are advised to block access to the api/notes/search-by-tag endpoint to protect their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
misskey < 13.3.3
