19
submitted 1 year ago by j_roby@slrpnk.net to c/meta@slrpnk.net

cross-posted from: https://sh.itjust.works/post/923025

lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.

It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.

you are viewing a single comment's thread
view the rest of the comments
[-] poVoq@slrpnk.net 5 points 1 year ago

I applied the mitigations and unvalidated all login tokens.

As far as I can tell slrpnk.net was not directly effected though.

this post was submitted on 10 Jul 2023
19 points (95.2% liked)

Meta (slrpnk.net)

505 readers
1 users here now

Here we can discuss anything about this Lemmy instance/server itself.

Our XMPP support chat: Movim or XMPP client.

Please also refer to our Wiki

founded 2 years ago
MODERATORS