PT-2025-15285 · Unknown · Cs2-Weaponpaints-Website
Published
2025-04-07
·
Updated
2025-04-07
·
CVE-2025-29594
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CS2-WeaponPaints-Website version 2.1.7
Description
A vulnerability exists in the errorpage.php file where user-controlled input is not adequately validated before being processed. Specifically, the
errorcode parameter in the $ GET superglobal can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure.Recommendations
For CS2-WeaponPaints-Website version 2.1.7, consider validating and sanitizing the
errorcode parameter in the $ GET superglobal to prevent unauthorized access and XSS attacks. As a temporary workaround, restrict access to the errorpage.php file until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cs2-Weaponpaints-Website