Vulnerability Details CVE-2023-28686
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.8%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2023-28686
-
-
-
cpe:2.3:a:dino:dino:0.1.0
-
cpe:2.3:a:dino:dino:0.1.1
-
cpe:2.3:a:dino:dino:0.1.2
-
cpe:2.3:a:dino:dino:0.2.0
-
cpe:2.3:a:dino:dino:0.2.1
-
cpe:2.3:a:dino:dino:0.3.0
-
cpe:2.3:a:dino:dino:0.4.0
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:11.0
-
cpe:2.3:o:debian:debian_linux:12.0
-
cpe:2.3:o:fedoraproject:fedora:36
-
cpe:2.3:o:fedoraproject:fedora:37
-
cpe:2.3:o:fedoraproject:fedora:38