First published: Mon Apr 29 2024(Updated: )
In Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telegram | <2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33905 is classified as a medium severity vulnerability due to its potential for XSS attacks.
To fix CVE-2024-33905, update Telegram WebK to version 2.0.0 or later.
CVE-2024-33905 facilitates Cross-Site Scripting (XSS) attacks through a crafted Mini Web App.
CVE-2024-33905 affects all versions of Telegram WebK before 2.0.0.
CVE-2024-33905 can lead to session hijacking and unauthorized actions in the Telegram WebK application.