The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39732.md | third party advisory exploit |
https://liff.line.me/1657574837-elb6bNQj | product |