Логотип exploitDog
bind:CVE-2019-18954
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-18954

Количество 2

Количество 2

nvd логотип

CVE-2019-18954

около 6 лет назад

Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4x6v-rwh4-55jw

около 6 лет назад

Pomelo allows external control of critical state data

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-18954

Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.

CVSS3: 5.3
0%
Низкий
около 6 лет назад
github логотип
GHSA-4x6v-rwh4-55jw

Pomelo allows external control of critical state data

CVSS3: 5.3
0%
Низкий
около 6 лет назад

Уязвимостей на страницу