CVE-2023-29192: low-severity vulnerability in mesosoi silverwaregames-io-issue-tracker
SilverwareGames.io users with access to the game upload panel are able to edit download links for games uploaded by other developers
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.7epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected products
mesosoi · silverwaregames-io-issue-trackerRelated CVEs — mesosoi silverwaregames-io-issue-tracker
In the same product, most dangerous first.
CVE-2022-36072MEDIUMSilverwareGames.io used == for hashing instead of ===EPSS 0.6%CVE-2023-40179MEDIUMSilverware Games vulnerable to account enumeration via inconsistent responsesEPSS 0.4%CVE-2023-40182LOWsilverware-io-issue-tracker server responds in a noticeably different amount of time depending if a given email address exists or notEPSS 0.4%CVE-2022-23543MEDIUMHTML attributes when attaching a YouTube link to the postEPSS 0.3%