cross-posted from: https://sh.itjust.works/post/923025
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.
It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.
why is your entire account dedicated to sucking reddit’s asshole. do you like the taste of corporate shit?
Yeah it’s so weird, why make an account here if he likes Reddit so much? We just want to have another place to have communities, that’s why we left and stayed here. He should do the same, stay there and out of here if he hates this place so much.
it’s honestly pathetic. he hates it here so much that he spends 95% of his free time here making comments about how much better reddit is hahaha. he seems addicted to this place and addicted to the taste of shiny black boots
This has nothing to do with XSS, it is a simple HTML injection vulnerability, and it can only be exploited by instance admins.
Also Lemmy.world appears to have been running a custom frontend so it’s hard to say how widespread the affects of this are.
Worst case scenario, they can steal your Lemmy session, right?
Which isn’t super bad for a service like Lemmy. This isn’t a social network, so most contact list scams would be useless.
Edit: just read the targets were admins. That IS bad.
It seems to have just gotten to Lemmy.blahaj.zone
Beehaw completely shut down as a response