PT-2023-27308 · Unknown · Silverware Games

Mesosoi

·

Publicado

2023-08-25

·

Atualizado

2023-08-30

·

CVE-2023-40179

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Silverware Games versions prior to 1.3.6
Description The issue concerns the Password Recovery form in Silverware Games, a premium social network for online gaming. Prior to version 1.3.6, the form would indicate whether an email address is associated with a site member by throwing an error if the email was not found in the database. This behavior allowed potential attackers to determine if a specific email address is linked to a user account. Since version 1.3.6, the form always returns the "Enter the code" page, displaying a message that a code will be sent if the email is associated with an account, thus preventing attackers from identifying email addresses linked to user accounts.
Recommendations For versions prior to 1.3.6, update to version 1.3.6 or later to prevent potential violators from determining if the site has a user with a specified email.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40179
GHSA-789J-CHFJ-58HR

Produtos afetados

Silverware Games