PT-2021-10814 · Portable · Portable Ltd Playable
Benjamin Kunz Mejri
·
Published
2021-10-22
·
Updated
2021-10-27
·
CVE-2020-23037
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Portable Ltd Playable version 9.18
Description
The issue allows attackers to execute arbitrary web scripts or HTML via a crafted POST request, exploiting a code injection vulnerability in the
filename parameter.Recommendations
For Portable Ltd Playable version 9.18, consider restricting access to the vulnerable
filename parameter to minimize the risk of exploitation until a patch is available. Avoid using the filename parameter in affected API endpoints until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Portable Ltd Playable