The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42187 | The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 02 Dec 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Nov 2024 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files | |
| Title | Game Extension Engine Path Traversal Vulnerability | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Vivo
Published:
Updated: 2024-12-02T11:19:36.615Z
Reserved: 2024-09-15T22:07:33.094Z
Link: CVE-2024-46939
Updated: 2024-12-02T11:17:16.044Z
Status : Received
Published: 2024-11-28T04:15:03.987
Modified: 2024-11-28T04:15:03.987
Link: CVE-2024-46939
No data.
OpenCVE Enrichment
No data.
EUVD