NA

CVE-2024-33905

Published: 29/04/2024 Updated: 01/05/2024

Vulnerability Summary

In Telegram WebK prior to 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.

Vulnerability Trend

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Telegram Web app XSS / Session Hijacking 1-click <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Pedro Batist ...