The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39740.md | third party advisory exploit |
https://liff.line.me/1657597257-0ozj8DwJ | product |