PT-2024-36612 · Unknown · Playloom Engine
Published
2024-12-13
·
Updated
2024-12-16
·
CVE-2024-55946
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Playloom Engine version 0.0.1
Description
The issue is related to data storage, specifically when using the collaboration features in Playloom Engine. When collaborating with another user, they may have access to personal information entered into the software, posing a risk to user privacy. The collaboration feature has been temporarily disabled by the maintainers until a fix can be implemented.
Recommendations
For Playloom Engine version 0.0.1, refrain from using the collaboration feature until the release of version 0.0.2, which is expected to contain a patch addressing this issue. As a temporary workaround, consider avoiding the use of the collaboration feature to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Playloom Engine