PT-2021-23164 · Roblox · Roblox-Purchasing-Hub

Highparker02311

·

Published

2021-10-27

·

Updated

2021-11-02

·

CVE-2021-41191

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Roblox-Purchasing-Hub versions 1.0.1 and prior
Description A security risk in Roblox-Purchasing-Hub allowed individuals with access to someone's API URL to obtain product files without an API key.
Recommendations For versions 1.0.1 and prior, update to version 1.0.2 to resolve the issue. As a temporary workaround for versions 1.0.1 and prior, consider adding @require apikey in BOT/lib/cogs/website.py under the route for "/v1/products".

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41191
GHSA-76MX-6584-4V8Q

Affected Products

Roblox-Purchasing-Hub