An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.
Link | Tags |
---|---|
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-43297.md | exploit |