mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 17:50:34 +00:00
18 lines
919 B
Markdown
18 lines
919 B
Markdown
![]() |
### [CVE-2019-18954](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18954)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://github.com/cl0udz/vulnerabilities/tree/master/pomelo-critical-state-manipulation
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ossf-cve-benchmark/CVE-2019-18954
|
||
|
|