CVE-2023-28686: High severity dino vulnerability
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28686?
CVE-2023-28686 is a vulnerability in Dino versions before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 that allows attackers to modify the personal bookmark store via a crafted message.
How can an attacker exploit CVE-2023-28686?
An attacker can exploit CVE-2023-28686 to change the display of group chats or force a victim to join a group chat, potentially tricking the victim into disclosing sensitive information.
What is the severity of CVE-2023-28686?
CVE-2023-28686 has a severity rating of 7.1 (high).
Which software versions are affected by CVE-2023-28686?
Dino versions before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 are affected by CVE-2023-28686.
How can I fix CVE-2023-28686?
To fix CVE-2023-28686, update Dino to version 0.2.3 or higher.