#VU74214 Spoofing attack in Dino - CVE-2023-28686

 

#VU74214 Spoofing attack in Dino - CVE-2023-28686

Published: March 30, 2023


Vulnerability identifier: #VU74214
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-28686
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Dino
Software vendor:
Dino Team

Description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can send a specially crafted message to the victim and modify their personal bookmark store, which can lead the victim into joining an untrusted group chat.


Remediation

Install updates from vendor's website.

External links