this post was submitted on 10 Jul 2023
118 points (93.4% liked)

Lemmy.World Announcements

29066 readers
3 users here now

This Community is intended for posts about the Lemmy.world server by the admins.

Follow us for server news ๐Ÿ˜

Outages ๐Ÿ”ฅ

https://status.lemmy.world

For support with issues at Lemmy.world, go to the Lemmy.world Support community.

Support e-mail

Any support requests are best sent to [email protected] e-mail.

Report contact

Donations ๐Ÿ’—

If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.

If you can, please use / switch to Ko-Fi, it has the lowest fees for us

Ko-Fi (Donate)

Bunq (Donate)

Open Collective backers and sponsors

Patreon

Join the team

founded 1 year ago
MODERATORS
 

We know an issue occurred on the site over an hour ago with someone using my account to redirect the site, make fake posts, and change other settings. The problem has been corrected.

We will continue to monitor the situation and keep you informed.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] AlmightySnoo 11 points 1 year ago (1 children)

Yes that's what allowed them to modify the contents of the sidebar, but the more serious problem is that you can put HTML in the sidebar and it won't be escaped by the Lemmy backend. That's what allowed this JavaScript redirection.

[โ€“] deweydecibel 9 points 1 year ago* (last edited 1 year ago) (1 children)

Should also be pointed out the admin is evidently still compromised. The one that posted this thread.

[โ€“] AlmightySnoo 4 points 1 year ago

I'm opening Pandora's box: what if all sidebars, not just the main one, have this vulnerability? An admin account being compromised will be the least of our worries if this is the case.