CVE-2023-24812 is a critical SQL injection vulnerability affecting Misskey, an open-source decentralized social media platform, in versions prior to 13.3.3. This flaw stems from insufficient parameter validation in the notes/search-by-tag API endpoint. With a CVSS score of 9.8 (CRITICAL), it allows unauthenticated attackers to remotely achieve full compromise (confidentiality, integrity, availability) with low attack complexity. While there is no evidence of active exploitation, no public exploit code, and minimal community discussion, users are strongly advised to upgrade to version 13.3.3 or block access to the affected API endpoint.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.3.3CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.