CVE-2024-33905
CVE-2024-33905 is a Cross-Site Scripting (XSS) vulnerability in Telegram WebK before version 2.0.0 (488). This flaw allows attackers to inject malicious scripts into the Telegram WebK application through a crafted Mini Web App, specifically leveraging the postMessage web_app_open_link
event type. The low SVRS score of 30 suggests a lower immediate risk compared to critical vulnerabilities, but the "In The Wild" tag indicates it's actively being exploited. An attacker could potentially steal sensitive user data or perform unauthorized actions on behalf of a user. While the CVSS score is 0, indicating no base severity, the presence "In The Wild" status elevates concern, underscoring the importance of applying the latest security patches. Mitigation involves updating Telegram WebK to a version 2.0.0 (489) or later. This vulnerability highlights the risks associated with untrusted web applications and the need for robust input validation and security measures in web applications.
Description
CVE-2024-33905 is a cross-site scripting (XSS) vulnerability in Telegram WebK before version 2.0.0 (488). An attacker could exploit this vulnerability by sending a crafted Mini Web App to a victim. When the victim opens the Mini Web App, the attacker could execute arbitrary JavaScript code in the victim's browser.
Key Insights
- The SVRS for CVE-2024-33905 is 30, indicating a low level of severity.
- This vulnerability is not currently being exploited in the wild.
- CISA has not issued a warning about this vulnerability.
Mitigation Strategies
- Update Telegram WebK to version 2.0.0 (488) or later.
- Use a web browser that supports XSS protection.
- Be cautious when opening links from unknown sources.
Additional Information
If you have any further questions about this incident, you can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.