this post was submitted on 10 Jul 2023
19 points (95.2% liked)
sh.itjust.works Main Community
7733 readers
1 users here now
Home of the sh.itjust.works instance.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
https://lemmy.world/post/1293336
Seems to be a pretty good summary? Feel free to ping me back if you need help understanding it.
Its a pretty straight forward XSS vulnerability. That basically means that the attacker got Javascript code execution upon the population, including the administrators. When you get Javascript execution, you almost always just steal cookies. Once the cookies to an administrator were stolen, then the admin-actions could be executed (such as changing the sidebar, making false posts / misinformation, etc. etc.)
https://lemmy.world/post/1299831
This link, too. Both the prior comment and this link post say the same thing for the most part with some variations.