PT-2024-17782 · Unknown · Treasurehuntgame Treasurehunt
Jotaespig
·
Published
2024-12-22
·
Updated
2025-01-10
·
CVE-2024-12895
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TreasureHuntGame TreasureHunt up to 963e0e0
Description
A critical vulnerability has been found in TreasureHuntGame TreasureHunt. The issue affects the
console log function of the file TreasureHunt/checkflag.php. The manipulation of the problema argument leads to SQL injection. This attack can be launched remotely.Recommendations
To fix this issue, it is recommended to apply a patch. Specifically, for versions up to 963e0e0, applying the patch with the identifier 8bcc649abc35b7734951be084bb522a532faac4e is advised. As a temporary workaround, consider restricting access to the
console log function in the TreasureHunt/checkflag.php file until the patch is applied. Additionally, avoid using the problema argument in the affected function until the issue is resolved.Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Treasurehuntgame Treasurehunt