The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39733.md | exploit |
https://liff.line.me/1656987103-bk5k9PO4 | product |