PT-2026-5728 · Talishar · Talishar
Bxsic-Fr
·
Published
2026-02-02
·
Updated
2026-02-03
·
CVE-2026-25144
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Talishar (affected versions not specified)
Description
A Stored Cross-Site Scripting (XSS) issue exists within the in-game chat system. The
playerID parameter in the 'SubmitChat.php' file is saved without proper sanitization. This unsanitized data is then executed when a user views the current game page. This allows for the injection of malicious scripts into the chat system, potentially affecting users who view the compromised chat messages.Recommendations
Versions prior to the commit 09dd00e5452e3cd998eb1406a88e5b0fa868e6b4 are vulnerable.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Talishar