CVE-2023-43805
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 4, 2023
Updated: Oct 11, 2023
CWE ID 287
Summary
CVE-2023-43805 is a vulnerability affecting the Nexkey social media platform, a fork of Misskey. Before version 12.121.9, the software failed to properly validate URLs, allowing unauthenticated users potential access to the job queue dashboard. This issue has been rectified with the release of version 12.121.9. As a temporary measure, administrators may utilize tools like Cloudflare's WAF to restrict access to vulnerable pages.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.