mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
686 B
686 B
CVE-2024-39828
Description
R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to 1.9.5 on 2024-06-29.
POC
Reference
- https://github.com/ggod2/sandboxels_xss_test
- https://github.com/ggod2/sandboxels_xss_test/blob/main/README.md