The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files
Metrics
Affected Vendors & Products
References
History
Mon, 02 Dec 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 28 Nov 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files | |
Title | Game Extension Engine Path Traversal Vulnerability | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: Vivo
Published: 2024-11-28T03:26:28.929Z
Updated: 2024-12-02T11:19:36.615Z
Reserved: 2024-09-15T22:07:33.094Z
Link: CVE-2024-46939
Vulnrichment
Updated: 2024-12-02T11:17:16.044Z
NVD
Status : Received
Published: 2024-11-28T04:15:03.987
Modified: 2024-11-28T04:15:03.987
Link: CVE-2024-46939
Redhat
No data.