http://tutacomm6oqwlbbpd246mljjxpupuxxqj2jg5mfdyegeaetdauigslad.onion/blog/vulnerability-fixed
The
RCE vulnerability enabled an attacker to execute programs on a user’s system via the desktop client (this was demonstrated
using Windows, but may have been possible on other operating systems), in which they take advantage of the XSS and use it
to download and execute a malicious attachment. What actions have we taken? Two days after being informed about the vulnerabilities, we have released a patch in version 3.98.1 which puts the
urlify call before the sanitization,...