PT-2022-16874 · Geon · Geon

Lobometalurgico

+1

·

Published

2022-03-24

·

Updated

2022-03-31

·

CVE-2022-24781

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Geon versions prior to 1.1.0
Description The issue allows malicious users to obtain the uuid from other users and spoof it through the browser console, becoming co-owners of the target session. This is related to the Geon board game, which focuses on solving questions about the Pythagorean Theorem.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the browser console to minimize the risk of uuid spoofing.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24781
GHSA-4FV9-G2JH-J5XM

Affected Products

Geon