Is there a write up for the Lemmy exploit that happened? Or can someone give me any specific? I’m a cybersecurity student and would like to learn a bit more.
Seems to be a pretty good summary? Feel free to ping me back if you need help understanding it.
Its a pretty straight forward XSS vulnerability. That basically means that the attacker got Javascript code execution upon the population, including the administrators. When you get Javascript execution, you almost always just steal cookies. Once the cookies to an administrator were stolen, then the admin-actions could be executed (such as changing the sidebar, making false posts / misinformation, etc. etc.)