CVE-2022-23543: medium-severity vulnerability in mesosoi silverwaregames-io-issue-tracker
HTML attributes when attaching a YouTube link to the post
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.3%
exploitation probability
0.3%top 74% of all CVEs
observed exploitation
nono source reports it
Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the site will generate related `<iframe>` when the post will be published. The handler has some sort of protection so non-YouTube links can't be posted, as well as HTML tags are being stripped. However, it was still possible to add custom HTML attributes (e.g. `onclick=alert("xss")`) to the `<iframe>'. This issue was fixed in the version `1.1.34` and does not require any extra actions from our members. There has been no evidence that this vulnerability was used by anyone at this time.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
mesosoi · silverwaregames-io-issue-trackerRelated CVEs — mesosoi silverwaregames-io-issue-tracker
In the same product, most dangerous first.
CVE-2022-36072MEDIUMSilverwareGames.io used == for hashing instead of ===EPSS 0.6%CVE-2023-40179MEDIUMSilverware Games vulnerable to account enumeration via inconsistent responsesEPSS 0.4%CVE-2023-40182LOWsilverware-io-issue-tracker server responds in a noticeably different amount of time depending if a given email address exists or notEPSS 0.4%CVE-2023-29192LOWSilverwareGames.io users with access to the game upload panel are able to edit download links for games uploaded by other developersEPSS 0.4%