logoalt Hacker News

llmslave2yesterday at 1:20 AM2 repliesview on HN

XSS is a RCE exploit. It allows you to run any action as if you were the owner of the account. How is that not a full account takeover?


Replies

collinmandersonyesterday at 5:21 PM

Yes, it's generally a "full account takeover" for a given discord user.

But RCE usually means ability to run any code on the web server, and would generally get you access to _everything_ including full direct access to the database. All accounts and all data, not just a few accounts.

rainonmoonyesterday at 1:29 AM

XSS is categorically not an RCE and my point is that mitigations exist which make "It allows you to run any action as if you were the owner of the account" an unwarranted assumption. The writeup shows that it's possible to pop an alert box. That doesn't tell you anything about what's actually possible. Obviously Discord got enough information to take it seriously, but extrapolating that to suggest every third-party using Mintlify is vulnerable to account takeover is highly dubious based on what's presented.

show 2 replies