CVE-2024-33905

Published
View on NVD ↗
CVSS v3
4.6
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

In Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.

Telegram Web K, GPL v3
GitHubGitHub
2.1K