CVE-2022-23543: falha de média gravidade em mesosoi silverwaregames-io-issue-tracker
HTML attributes when attaching a YouTube link to the post
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.3epss 0.3%
probabilidade de exploração
0.3%top 74% das CVEs
exploração observada
nãonenhuma fonte reporta
Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the site will generate related `<iframe>` when the post will be published. The handler has some sort of protection so non-YouTube links can't be posted, as well as HTML tags are being stripped. However, it was still possible to add custom HTML attributes (e.g. `onclick=alert("xss")`) to the `<iframe>'. This issue was fixed in the version `1.1.34` and does not require any extra actions from our members. There has been no evidence that this vulnerability was used by anyone at this time.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Produtos afetados
mesosoi · silverwaregames-io-issue-trackerCVEs relacionadas — mesosoi silverwaregames-io-issue-tracker
No mesmo produto, das mais perigosas para as menos.
CVE-2022-36072MEDIUMSilverwareGames.io used == for hashing instead of ===EPSS 0.6%CVE-2023-40179MEDIUMSilverware Games vulnerable to account enumeration via inconsistent responsesEPSS 0.4%CVE-2023-40182LOWsilverware-io-issue-tracker server responds in a noticeably different amount of time depending if a given email address exists or notEPSS 0.4%CVE-2023-29192LOWSilverwareGames.io users with access to the game upload panel are able to edit download links for games uploaded by other developersEPSS 0.4%