Impact
The vulnerability in the MintyItanium Lost-Auction plugin allows a player to manipulate the in‑game search GUI to retrieve items such as barrier blocks or duplicate existing items. This flaw effectively bypasses the intended item restriction controls, enabling players to gain items they should not possess. The weakness is a form of incorrect authorization, leading to unauthorized data modification within the game environment.
Affected Systems
Any Minecraft server running the MintyItanium Lost-Auction plugin before the commit identified by 88c920b05042929db334ba06d57f052b42d6b3f8 is affected. The plugin is released by MintyItanium under the Lost-Auction label.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and there is no EPSS score available, suggesting limited publicly known exploitation activity. The issue was listed as not in the CISA KEV catalog. Attackers can exploit the flaw by simply engaging the GUI on a server that has not applied the recent patch; no external network vector is required.
OpenCVE Enrichment