PT-2022-16874 · Geon · Geon
Lobometalurgico
+1
·
Published
2022-03-24
·
Updated
2022-03-31
·
CVE-2022-24781
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Geon versions prior to 1.1.0
Description
The issue allows malicious users to obtain the
uuid from other users and spoof it through the browser console, becoming co-owners of the target session. This is related to the Geon board game, which focuses on solving questions about the Pythagorean Theorem.Recommendations
For versions prior to 1.1.0, update to version 1.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the browser console to minimize the risk of
uuid spoofing.Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geon