PT-2024-36803 · Lgsl · Lgsl
Onsali
·
Published
2024-12-26
·
Updated
2024-12-27
·
CVE-2024-56361
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LGSL versions prior to 7.0.0
Description
A stored cross-site scripting (XSS) vulnerability was identified in LGSL. The issue arises from improper sanitation of user input. The function
lgsl query 40 in lgsl protocol.php has implemented an HTTP crawler, which makes a request to the registered game server and renders javascript on the info page when crawling the malicious /info endpoint with a payload. This information is being displayed via lgsl details.php. Everyone who accesses this page will be affected by this attack.Recommendations
For versions prior to 7.0.0, update to version 7.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the
lgsl query 40 function in lgsl protocol.php until a patch is available. Restrict access to the /info endpoint to minimize the risk of exploitation. Avoid using the EconomyDesc field in the JSON payload served at /info until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lgsl